MJP Security Tools is a focused hardening plugin that does four things well:
<script>, <iframe>, onclick, javascript: and other injection patternsindex.html files and SVN working copiesWhat this plugin does NOT do (because WordPress core already handles it):
FORCE_SSL_ADMIN or let WordPress 5.7+ auto-redirectUpgrading from v1.x: