{"id":364462,"date":"2026-09-11T06:56:18","date_gmt":"2026-09-11T06:56:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/hopelessly-sensible-simple-security-hardening\/"},"modified":"2026-09-11T06:55:50","modified_gmt":"2026-09-11T06:55:50","slug":"hopelessly-sensible","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/hopelessly-sensible\/","author":23551246,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.1","stable_tag":"1.1.1","tested":"7.1","requires":"6.5","requires_php":"7.4","requires_plugins":null,"header_name":"Hopelessly Sensible: Simple Security Hardening","header_author":"Hebble & Stone","header_description":"Security hardening for people who have better things to do.","assets_banners_color":"f8f8eb","last_updated":"2026-09-11 06:55:50","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/Hebble-Stone-CIC\/hopelessly-sensible","header_author_uri":"https:\/\/hebblestone.org","rating":5,"author_block_rating":0,"active_installs":0,"downloads":53,"num_ratings":1,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","faq","changelog"],"tags":{"1.1.1":{"tag":"1.1.1","author":"hebblestone","date":"2026-09-11 06:55:50","revision":3690937}},"upgrade_notice":[],"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3690973,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3690973,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3690973,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3690973,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.1.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3690973,"resolution":"1","location":"assets","locale":"","width":1920,"height":1776},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3690973,"resolution":"2","location":"assets","locale":"","width":1920,"height":1636}},"screenshots":{"1":"The settings screen. Every option carries a plain explanation and a note on what it might break.","2":"An option this site cannot use, still on the screen, saying what is stopping it."}},"plugin_section":[],"plugin_tags":[107,31093,396,600,14731],"plugin_category":[44,54],"plugin_contributors":[280190,280189],"plugin_business_model":[],"class_list":["post-364462","plugin","type-plugin","status-publish","hentry","plugin_tags-comments","plugin_tags-hardening","plugin_tags-privacy","plugin_tags-security","plugin_tags-xmlrpc","plugin_category-discussion-and-community","plugin_category-security-and-spam-protection","plugin_contributors-hebblestone","plugin_contributors-mattbedford","plugin_committers-hebblestone"],"banners":{"banner":"https:\/\/ps.w.org\/hopelessly-sensible\/assets\/banner-772x250.png?rev=3690973","banner_2x":"https:\/\/ps.w.org\/hopelessly-sensible\/assets\/banner-1544x500.png?rev=3690973","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/hopelessly-sensible\/assets\/icon-128x128.png?rev=3690973","icon_2x":"https:\/\/ps.w.org\/hopelessly-sensible\/assets\/icon-256x256.png?rev=3690973","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/hopelessly-sensible\/assets\/screenshot-1.png?rev=3690973","caption":"The settings screen. Every option carries a plain explanation and a note on what it might break."},{"src":"https:\/\/ps.w.org\/hopelessly-sensible\/assets\/screenshot-2.png?rev=3690973","caption":"An option this site cannot use, still on the screen, saying what is stopping it."}],"raw_content":"<!--section=description-->\n<p>Most security plugins are built for people who enjoy security. This one is built for everyone else: the person who looks after a small charity's website on a Tuesday evening and would like to stop worrying about it.<\/p>\n\n<p>It does seven things. Each one has a switch, a plain-English explanation of what it does, and an honest note about what it might break. No notification badges, no upgrade prompts, no counting of attacks repelled, and nothing anywhere in your dashboard trying to sell you something.<\/p>\n\n<p><strong>It describes your site as it is today.<\/strong><\/p>\n\n<p>Everything on the settings screen is about your site now, not about what it looked like the day you installed this. If four people publish posts here, it says four. If three comments are approved and hidden from your visitors, it says so, and tells you how to get rid of them for good if that is what you want.<\/p>\n\n<p><strong>It sets up what is safe, and leaves the rest to you.<\/strong><\/p>\n\n<p>When you activate it, the plugin looks at your site and switches on what is safe here. If you have one writer, it hides author pages. If nobody has approved a comment in a year, it closes comments. Three of the seven are never switched on for you, because they take something away from you rather than from a visitor, and that decision is yours to make.<\/p>\n\n<p><strong>If something changes, it stands down and tells you.<\/strong><\/p>\n\n<p>If a setting stops being safe to leave on, this plugin switches it off by itself. Install something that needs remote publishing and blocking remote publishing goes off, rather than sitting there reading as on while quietly breaking your new plugin. When that happens you get one notice, once, saying what changed and why, and you can dismiss it for good. It is the only thing this plugin will ever show you outside its own settings screen, and it only ever appears because something has already happened.<\/p>\n\n<p>A switch that is off is never turned on behind your back. That direction is always yours.<\/p>\n\n<p><strong>What it does<\/strong><\/p>\n\n<ul>\n<li>Keeps your list of users and their usernames away from anonymous visitors<\/li>\n<li>Gives the same short message whether a login failed on the username or the password<\/li>\n<li>Hides author pages, and keeps writers out of your sitemap and link previews<\/li>\n<li>Blocks XML-RPC, an old remote publishing interface popular with password-guessing tools<\/li>\n<li>Closes comments everywhere, and leaves WooCommerce reviews alone unless you say otherwise<\/li>\n<li>Closes WooCommerce product reviews, if you want that<\/li>\n<li>Locks the theme and plugin file editors in the dashboard<\/li>\n<li>Warns you if you have a user called \"admin\", and does nothing else about it<\/li>\n<\/ul>\n\n<p><strong>What it does not do<\/strong><\/p>\n\n<ul>\n<li>It does not write to your .htaccess file, your wp-config.php, or anything outside its own single settings row. Deactivate it and your site is exactly as it was, immediately.<\/li>\n<li>It adds no JavaScript to your dashboard.<\/li>\n<li>It does not scan, does not phone home, does not collect anything, and has no paid version.<\/li>\n<li>It does not give you homework. There is no checklist, no score, and no red badge waiting for you.<\/li>\n<li>It does not hide options from you. Anything this plugin cannot do on your site is still on the screen, switched off, saying what is stopping it.<\/li>\n<\/ul>\n\n<p>Free and open source, GPL, written by Hebble &amp; Stone, a community interest company that builds websites for charities.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"will%20this%20break%20my%20site%3F\"><h3>Will this break my site?<\/h3><\/dt>\n<dd><p>Any of these settings can change how something works, which is why each one carries a warning saying what. The two that most often surprise people are closing comments, which hides discussion your visitors may be part of and takes the Comments screen out of your dashboard while it is on, and locking the file editor, which stops you editing theme files from the dashboard. Both are explained on the settings screen before you touch them. Nothing is deleted either way: switch comments back on and everything is where you left it.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20deactivate%20it%3F\"><h3>What happens if I deactivate it?<\/h3><\/dt>\n<dd><p>Everything goes back to how it was, straight away. The plugin makes no permanent changes to your site, so there is nothing to undo. Uninstalling removes its single row from your options table.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20woocommerce%3F\"><h3>Does it work with WooCommerce?<\/h3><\/dt>\n<dd><p>Yes, and carefully. WooCommerce reviews are stored as comments, so closing comments would ordinarily take your product reviews and star ratings with them. This plugin never does that. Reviews have their own separate option, off by default, which sits on the screen switched off and explained if WooCommerce is not installed. Order notes, which are also stored as comments, are never touched by anything here.<\/p>\n\n<p>One thing to know if your shop is running an old WooCommerce. Closing comments takes the Comments screen out of your dashboard, and WooCommerce moved review moderation to its own screen under Products in version 6.7. On WooCommerce 6.7 or later this is fine, and you carry on approving reviews as normal. On anything older, reviews are still moderated on the Comments screen, so this plugin leaves that screen reachable on those shops rather than taking review moderation away from you.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20multisite%3F\"><h3>Does it work on multisite?<\/h3><\/dt>\n<dd><p>Yes, but activate it on each site rather than across the whole network. Activating for the network means it cannot look at your sites one by one, so every option starts where it starts rather than where the plugin would have put it, and it says so on the settings screen. Activated site by site, it looks at each one properly. Either way the settings are per site, so what you choose on one site does not affect another.<\/p><\/dd>\n<dt id=\"will%20it%20stop%20someone%20hacking%20my%20site%3F\"><h3>Will it stop someone hacking my site?<\/h3><\/dt>\n<dd><p>No plugin can promise that, and you should be wary of any that implies it. This one closes off a set of well-known ways that automated tools gather information and guess passwords. That is worth doing, and it is not the same thing as being safe. Strong passwords, two-factor authentication, and keeping WordPress and its plugins updated matter more than anything here.<\/p><\/dd>\n<dt id=\"why%20is%20there%20no%20scanning%2C%20firewall%2C%20or%20login%20limiting%3F\"><h3>Why is there no scanning, firewall, or login limiting?<\/h3><\/dt>\n<dd><p>Because those need attention, and this plugin is built to be set once and forgotten. Features that generate alerts generate work, and work gets ignored, and ignored alerts are worse than no alerts.<\/p><\/dd>\n<dt id=\"i%20have%20a%20user%20called%20%22admin%22%20and%20it%20is%20warning%20me.%20what%20do%20i%20do%3F\"><h3>I have a user called \"admin\" and it is warning me. What do I do?<\/h3><\/dt>\n<dd><p>WordPress does not let you rename a user. The usual route is to create a second administrator account with a different username, log in as that one, delete the \"admin\" account, and hand its posts over to the new account when WordPress asks.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.1<\/h4>\n\n<ul>\n<li>Changed: three messages borrowed from WordPress itself (the vague login error, the remote publishing refusal and the user list refusal) are now translatable as part of this plugin, as the plugin directory requires, rather than inheriting the translations WordPress ships with.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Fixed: on WordPress 7.1, \"Block remote publishing\" could not be switched on at all, and switched itself off on sites that had it on. WordPress 7.1 began using the same hook this plugin watches to work out whether anything on your site needs remote publishing, and the plugin read that as your site needing it.<\/li>\n<li>Added: \"Lock the file editor\" is now blocked, with an explanation, on sites where a published GeneratePress element runs PHP. GeneratePress stops running that code while the editor is locked, and prints the code into the page instead.<\/li>\n<li>Changed: the warning under \"Lock the file editor\" now mentions code snippets plugins, some of which stop running their code when the editor is locked.<\/li>\n<li>Tested against WordPress 7.1.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>First release.<\/li>\n<\/ul>","raw_excerpt":"Security hardening for people who have better things to do. Seven options, plain English, and an honest warning on every one.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/364462","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=364462"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/hebblestone"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=364462"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=364462"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=364462"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=364462"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=364462"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=364462"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}