

Settings panel — modules rendered as cards with toggles and descriptions.
WT Hardening is a lightweight, modular security plugin that turns on the most important WordPress hardening measures without modifying your theme, wp-config.php, or .htaccess. Everything works through WordPress hooks and can be disabled at any moment with a single click.
The plugin is completely free, without a PRO version, without ads, and without sending data to external servers. Built by the webmasters.team crew for daily WordPress work.
xmlrpc.php (403) and filters the XML-RPC methods. Stops brute-force attacks through the most attacked WordPress endpoint./wp/v2/users in the REST API for unauthenticated users./?author=1 to the homepage (another enumeration vector).<meta name="generator"> tag, ?ver= query strings from assets, and redundant meta tags (wlwmanifest, rsd, shortlink).X-Pingback HTTP header from all responses.wp_options), with hourly cleanup of old entries.DISALLOW_FILE_EDIT, hiding the theme and plugin editor in the admin (an attacker who compromises an account cannot inject a backdoor through the browser).X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, optionally HSTS (use with care — browsers cache it for a year).__()/esc_html__() and a POT file for translators.For those needs we recommend dedicated plugins (e.g. Wordfence) or an infrastructure layer (Cloudflare, fail2ban).