WP Manifestindependent plugin directory
manifest / security / hardening-essentials

Hardening Essentials

Ten independent WordPress hardening switches on one native settings page. No scanner, no firewall, no bundled extras.

by George Vasiliades · github.com/poseidonas/hardening-essentials · website

0stars
1release downloads
0forks

Install

The author publishes release zips, so WP-CLI can install straight from GitHub:

wp plugin install https://github.com/poseidonas/hardening-essentials/releases/download/v1.0.0/hardening-essentials.zip

Declares an update source (https://github.com/Poseidonas/hardening-essentials), so updates arrive through the plugin's own updater.

Readme

Hardening Essentials

Latest release WordPress 6.7+ PHP 8.0+ License GPL-2.0-or-later

Ten independent WordPress hardening switches on one native settings page. No scanner, no firewall, no bundled extras.

What it does

The plugin adds a page under Settings > Hardening with ten checkboxes. Each one is independent and takes effect as soon as the settings are saved.

Switch Effect Default
Disable XML-RPC Answers every XML-RPC request with HTTP 403, removes the X-Pingback header and the RSD discovery link. On
Block user enumeration Returns 404 for ?author=N requests from visitors, hides /wp/v2/users and the users sitemap from visitors, removes author details from oEmbed responses. Pretty author archives keep working. On
Disable file editors Removes the theme and plugin file editors from the dashboard. On
Hide version information Removes the generator tag, the WordPress version from core asset URLs and the X-Powered-By header. On
Disable pingbacks and trackbacks Removes the pingback XML-RPC methods and closes pings on all content. On
Generic login errors Wrong username and wrong password produce the same message. On
Send security headers Adds X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN and Referrer-Policy: strict-origin-when-cross-origin to front-end responses. On
Disable application passwords Turns off application passwords for all users. Off
Block PHP execution in uploads (Apache) Writes rules to wp-content/uploads/.htaccess that deny access to PHP files. Off
Disable directory listing and protect sensitive files (Apache) Writes Options -Indexes and denies access to wp-config.php, readme.html and license.txt in the root .htaccess. Off

The two Apache switches write rules between # BEGIN Hardening Essentials and # END Hardening Essentials markers. After writing, the plugin requests the site once and reverts the rules if the server answers with an HTTP 5xx status. The rules are removed when the switch is turned off, when the plugin is deactivated and when it is uninstalled. On servers that do not report Apache or LiteSpeed the two switches are unavailable and the page shows the equivalent Nginx directives.

Settings

Settings > Hardening. Requires the manage_options capability. The interface is in English and switches to Greek automatically when the site or the user language is Greek.

Filters

  • icxcnika_hardening_settings - array of switches before they are applied.
  • icxcnika_hardening_login_error_message - the generic login error text.
  • icxcnika_hardening_security_headers - associative array of headers sent to the front end.
  • icxcnika_hardening_uploads_rules - lines written to the uploads .htaccess.
  • icxcnika_hardening_root_rules - lines written to the root .htaccess.
  • icxcnika_hardening_registry_payload - data sent to the installation registry.

Data stored

  • Option icxcnika_hardening_settings (the ten switches).
  • Option icxcnika_hardening_registry_key (random installation key, created only if installation reporting is active).
  • Transient icxcnika_hardening_release (cached GitHub release lookup, 12 hours).
  • Cron event icxcnika_hardening_registry_ping (weekly).
  • Marker blocks in the root .htaccess and wp-content/uploads/.htaccess while the two Apache switches are on.

Installation reporting

On activation, on deactivation and once a week the plugin sends a small JSON message to the author's installation registry: plugin slug, plugin version, home URL, site URL, WordPress version, WooCommerce version if present, PHP version, locale and whether the site is a multisite. Each request carries a random installation key that is generated locally on first use and identifies the installation, not the user. No content, no user data and no personal data are sent. The settings page states this explicitly and shows the registered site URL. Add define( 'ICXCNIKA_REGISTRY_DISABLE', true ); to wp-config.php to turn the reporting off, or define( 'ICXCNIKA_REGISTRY_URL', '...' ); to point it elsewhere.

Updates

Updates are delivered from GitHub Releases of this repository. WordPress shows them on the Plugins screen like any other update.

Uninstall

Deleting the plugin removes the option, the transient, the cron event and the marker blocks from both .htaccess files. Nothing is left behind.


Hardening Essentials (Ελληνικά)

Δέκα ανεξάρτητοι διακόπτες θωράκισης του WordPress σε μία native σελίδα ρυθμίσεων. Χωρίς scanner, χωρίς firewall, χωρίς πρόσθετα.

  • Δημιουργός: George Vasiliades - https://github.com/Poseidonas
  • Άδεια: GPL-2.0-or-later
  • Απαιτεί WordPress 6.7+ και PHP 8.0+

Τι κάνει

Το plugin προσθέτει μια σελίδα στο Ρυθμίσεις > Hardening με δέκα checkboxes. Το καθένα είναι ανεξάρτητο και εφαρμόζεται μόλις αποθηκευτούν οι ρυθμίσεις.

Διακόπτης Ενέργεια Προεπιλογή
Απενεργοποίηση XML-RPC Απαντά σε κάθε αίτημα XML-RPC με HTTP 403, αφαιρεί το header X-Pingback και το RSD link. Ενεργό
Αποκλεισμός απαρίθμησης χρηστών Επιστρέφει 404 σε αιτήματα ?author=N από επισκέπτες, κρύβει το /wp/v2/users και το sitemap χρηστών από επισκέπτες, αφαιρεί τα στοιχεία συντάκτη από τις απαντήσεις oEmbed. Τα φιλικά αρχεία συντακτών συνεχίζουν να λειτουργούν. Ενεργό
Απενεργοποίηση επεξεργαστών αρχείων Αφαιρεί τους επεξεργαστές αρχείων θέματος και πρόσθετων από τον πίνακα ελέγχου. Ενεργό
Απόκρυψη πληροφοριών έκδοσης Αφαιρεί το generator tag, την έκδοση WordPress από τα URLs των αρχείων του πυρήνα και το header X-Powered-By. Ενεργό
Απενεργοποίηση pingbacks και trackbacks Αφαιρεί τις μεθόδους pingback του XML-RPC και κλείνει τα pings σε όλο το περιεχόμενο. Ενεργό
Γενικά μηνύματα σφάλματος σύνδεσης Λάθος όνομα χρήστη και λάθος κωδικός δίνουν το ίδιο μήνυμα. Ενεργό
Αποστολή security headers Προσθέτει X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN και Referrer-Policy: strict-origin-when-cross-origin στις απαντήσεις του front-end. Ενεργό
Απενεργοποίηση application passwords Κλείνει τα application passwords για όλους τους χρήστες. Ανενεργό
Αποκλεισμός εκτέλεσης PHP στα uploads (Apache) Γράφει κανόνες στο wp-content/uploads/.htaccess που απαγορεύουν την πρόσβαση σε αρχεία PHP. Ανενεργό
Απενεργοποίηση λίστας καταλόγων και προστασία ευαίσθητων αρχείων (Apache) Γράφει Options -Indexes και απαγορεύει την πρόσβαση σε wp-config.php, readme.html και license.txt στο ριζικό .htaccess. Ανενεργό

Οι δύο διακόπτες Apache γράφουν κανόνες ανάμεσα στους δείκτες # BEGIN Hardening Essentials και # END Hardening Essentials. Μετά την εγγραφή το plugin κάνει ένα αίτημα προς το site και αναιρεί τους κανόνες αν ο server απαντήσει με HTTP 5xx. Οι κανόνες αφαιρούνται όταν κλείσει ο διακόπτης, όταν απενεργοποιηθεί το plugin και όταν απεγκατασταθεί. Σε servers που δεν δηλώνουν Apache ή LiteSpeed οι δύο διακόπτες δεν είναι διαθέσιμοι και η σελίδα εμφανίζει τις αντίστοιχες οδηγίες Nginx.

Ρυθμίσεις

Ρυθμίσεις > Hardening. Απαιτεί τη δυνατότητα manage_options. Το περιβάλλον είναι στα Αγγλικά και γυρίζει αυτόματα στα Ελληνικά όταν η γλώσσα του site ή του χρήστη είναι Ελληνικά.

Φίλτρα

  • icxcnika_hardening_settings - ο πίνακας των διακοπτών πριν εφαρμοστούν.
  • icxcnika_hardening_login_error_message - το γενικό μήνυμα σφάλματος σύνδεσης.
  • icxcnika_hardening_security_headers - συσχετιστικός πίνακας με τα headers που στέλνονται στο front-end.
  • icxcnika_hardening_uploads_rules - οι γραμμές που γράφονται στο .htaccess των uploads.
  • icxcnika_hardening_root_rules - οι γραμμές που γράφονται στο ριζικό .htaccess.
  • icxcnika_hardening_registry_payload - τα δεδομένα που στέλνονται στο μητρώο εγκαταστάσεων.

Δεδομένα που αποθηκεύονται

  • Option icxcnika_hardening_settings (οι δέκα διακόπτες).
  • Option icxcnika_hardening_registry_key (τυχαίο κλειδί εγκατάστασης, δημιουργείται μόνο αν είναι ενεργή η αναφορά εγκατάστασης).
  • Transient icxcnika_hardening_release (cache της αναζήτησης έκδοσης στο GitHub, 12 ώρες).
  • Cron event icxcnika_hardening_registry_ping (εβδομαδιαίο).
  • Μπλοκ δεικτών στο ριζικό .htaccess και στο wp-content/uploads/.htaccess όσο οι δύο διακόπτες Apache είναι ενεργοί.

Αναφορά εγκατάστασης

Κατά την ενεργοποίηση, την απενεργοποίηση και μία φορά την εβδομάδα το plugin στέλνει ένα μικρό μήνυμα JSON στο μητρώο εγκαταστάσεων του δημιουργού: slug και έκδοση του plugin, home URL, site URL, έκδοση WordPress, έκδοση WooCommerce αν υπάρχει, έκδοση PHP, γλώσσα και αν το site είναι multisite. Κάθε αίτημα συνοδεύεται από ένα τυχαίο κλειδί εγκατάστασης που δημιουργείται τοπικά την πρώτη φορά και ταυτοποιεί την εγκατάσταση, όχι τον χρήστη. Δεν αποστέλλεται περιεχόμενο, δεδομένα χρηστών ή προσωπικά δεδομένα. Η σελίδα ρυθμίσεων το δηλώνει ρητά και εμφανίζει το URL του καταχωρημένου site. Προσθέστε define( 'ICXCNIKA_REGISTRY_DISABLE', true ); στο wp-config.php για να απενεργοποιήσετε την αναφορά, ή define( 'ICXCNIKA_REGISTRY_URL', '...' ); για να τη στείλετε αλλού.

Ενημερώσεις

Οι ενημερώσεις έρχονται από τα GitHub Releases αυτού του αποθετηρίου. Το WordPress τις εμφανίζει στη σελίδα Πρόσθετα όπως κάθε άλλη ενημέρωση.

Απεγκατάσταση

Η διαγραφή του plugin αφαιρεί το option, το transient, το cron event και τα μπλοκ δεικτών και από τα δύο αρχεία .htaccess. Δεν μένει τίποτα πίσω.

Read the full README on GitHub →

Releases

TagPublishedAssetDownloads
v1.0.0 Aug 18, 2026 hardening-essentials.zip 1