Lightweight, modular WordPress security hardening — XML-RPC blocker, login limiter, security headers, event log, and more. Free and open-source.
WT Hardening enables the most important WordPress hardening practices through hooks — without modifying your theme, wp-config.php, or .htaccess. Every module is independent and can be toggled in the admin panel. No external APIs, no telemetry, no PRO version.
/wp/v2/users for guests?author=1 to homepageDISALLOW_FILE_EDITSearch for "WT Hardening" in Plugins → Add new in your WordPress admin, or upload the ZIP manually. Activate, open the WT Hardening menu, and configure modules — they all start with safe defaults.
For bug reports and questions use the official support forum on WordPress.org or write to [email protected].