> SAR One Click Security wordpress plugin resources analysis

SAR One Click Security wordpress plugin resources analysis

Download This Plugin
Download Elegant Themes
Name SAR One Click Security
Version 1.1
Author Samuel Aguilera
Rating 100
Last updated 2014-09-30 10:51:00
Downloads
557
Download Plugins Speed Test plugin for Wordpress

Home page

Delta: 0%

Post page

Delta: 0%
SAR One Click Security plugin has no negative impact on PageSpeed score.

Home page PageSpeed score has been degraded by 0%, while Post page PageSpeed score has been degraded by 0%

SAR One Click Security plugin added 2 bytes of resources to the Home page and 2 bytes of resources to the sample Post page.

SAR One Click Security plugin added 0 new host(s) to the Home page and 0 new host(s) to the sample Post page.

Great! SAR One Click Security plugin ads no tables to your Wordpress blog database.

There's a lot of WordPress security plugins with many many options and pages to setup. And that is fine if you know what to do. But most of the times, you don't need so much or simply you're not sure about what to set or not.

This plugin adds some extra security to your WordPress with only one click. No options page, just activate it!

Features

Like many other security plugins SAR One Click Security adds well known .htaccess rules, but only the ones probed to be safe to use in almost any type of site (including WooCommerce stores), to protect your WordPress from common attacks. This allows you to have a safer WordPress without worries about what protection you should be using.

  • Turn off ServerSignature directive, that may leak information about your web server.
  • Turn off directoy listing, avoiding bad configured hostings to leak your files.
  • Blocks public access (from web) to following files that may leak information about your WordPress install: .htacces, license.txt, readme.html, wp-config.php, wp-config-sample.php
  • Blocks access to wp-login.php to dummy bots trying to register in WordPress sites that have registration disabled.
  • Blocks requests looking for timthumb.php, reducing server load caused by bots trying to find it. (*)
  • Blocks TRACE and TRACK request methods, preventing XST attacks.
  • Blocks direct posting to wp-comments-post.php (most spammers do this) and access with blank User Agent, reducing spam comments a lot and also server load.
  • Blocks direct access to PHP files in wp-content directory (this includes subdirectories like plugins or themes). Protecting you from a huge number of 0day exploits.
  • Blocks direct POST to wp-login.php and access with blank User Agent, preventing most brute-force attacks and reducing server load.

(*) If your theme uses TimThumb, you can disable that blocking rule, check FAQ before installing the plugin to see how.

Requirements

  • WordPress 3.9.2 or higher. (Works with WordPress network/multisite installation).
  • Apache2 web server

It has been tested in many servers including large providers like HostGator, Godaddy and 1&1 with optimal results, and it will work fine in any decent hosting service (that allows you to set options from .htaccess files).

Anyway, if you get any problem after activating the plugin, check FAQ for instructions on how to manually uninstall it. Or maybe check it before install the plugin if you're not sure about your hosting provider policy about .htacces

Usage

To apply above mentioned security rules simply install and activate the plugin, no options page, no user setup!

If you need to remove the security rules for some reason, simply deactivate the plugin. If you want to add them again, activate the plugin again, that easy ;)

And remember, if your theme uses TimThumb, check FAQ before installing the plugin.

Known issues

There are some plugins that uses direct access to .php files in the wp-conteng/plugins/ directory. That, in my honest opinion, is bad practice and should be avoided.

If you use some of these plugins, you can't use this.

Some plugins detected with this behaviour:

  • Google Doc Embedder
  • Yet Another Related Posts Plugin (YARPP)
Resources added by plugin to Home page/Post page in kB
Total size of resources for Home page/Post page in kB
Random Theme Tests
DarkElements screenshot

DarkElements

by: Guido07111975

1602
0%
PressPlay screenshot

PressPlay

by: SeventhSteel

63738
0%