PLUGIN SECURITY
Is Really Simple Ssl safe?
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate.
What this plugin does
- Slug:
really-simple-ssl - Author: Really Simple Plugins
- 3000000+ active installs
- 98/100 rating (8862 reviews on wordpress.org)
- 217501333 all-time downloads
- On WordPress.org since 2015-03-15
2FAhttpssecuritytwo factorvulnerabilities
Maintenance status
- Latest known version: 9.7.0
- Last updated: 2026-08-24 9:03am GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
7 known CVEs on file for Really Simple Ssl. Reported between 2024 and 2026.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| CVE-2026-48969 | Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] < 9.5.10 | Missing Authorization | Medium 6.5 | < 9.5.10 | 9.5.10 | 2026-06-03 | ✓ fixed in latest |
| CVE-2026-48970 | Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] < 9.5.10.1 | Authentication Bypass Using an Alternate Path or Channel | High 8.1 | < 9.5.10.1 | 9.5.10.1 | 2026-06-03 | ✓ fixed in latest |
| CVE-2026-8293 | Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] < 9.5.10.1 | Improper Authentication | Unknown | < 9.5.10.1 | 9.5.10.1 | 2026-06-02 | ✓ fixed in latest |
| CVE-2026-32461 | Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] < 9.5.8 | Missing Authorization | Medium 4.3 | < 9.5.8 | 9.5.8 | 2026-03-13 | ✓ fixed in latest |
| CVE-2025-24623 | Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] < 9.2.0 | Cross-Site Request Forgery (CSRF) | Medium 4.3 | < 9.2.0 | 9.2.0 | 2025-01-24 | ✓ fixed in latest |
| CVE-2024-10924 | Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] >= 9.0.0 - <= 9.1.1.1 | Authentication Bypass Using an Alternate Path or Channel | Critical 9.8 | 9.0.0–9.1.2 | 9.1.2 | 2024-11-14 | ✓ fixed in latest |
| CVE-2024-31229 | Really Simple Security – Simple and Performant Security (formerly Really Simple SSL) [really-simple-ssl] < 8.0.0 | Server-Side Request Forgery (SSRF) | Medium 5.5 | < 8.0.0 | 8.0.0 | 2024-04-16 | ✓ fixed in latest |
How to fix it
Keep Really Simple Ssl updated — 9.7.0 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Wordfence Security – Firewall, Malware Scan, and Login Security — 5000000+ active installs — 94/100 (4981) — max PHP 8.4
- Hostinger Tools — 3000000+ active installs — 70/100 (40) — max PHP 8.4
- Limit Login Attempts Security – Login Security, 2FA, Firewall, Brute Force Prevention — 1000000+ active installs — 96/100 (1477) — max PHP 8.4
- Two Factor — 100000+ active installs — 96/100 (208) — max PHP 8.4
- WP 2FA – Two-factor authentication for WordPress — 100000+ active installs — 94/100 (176)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.