.htaccess Generator
301 redirects, force HTTPS, www/non-www, protect wp-config and xmlrpc, hotlink protection, compression and caching. Open ›
Free online tools that come in handy when building and maintaining WordPress sites. They all run entirely in your browser, with no data sent to a server.
Assemble a ready-to-use hardening configuration for WordPress for an Apache / LiteSpeed or nginx server plus wp-config.php: protecting sensitive files, blocking PHP execution in uploads, disabling xmlrpc and author enumeration, security headers and panel hardening. Risky rules are clearly flagged.
301 redirects, force HTTPS, www/non-www, protect wp-config and xmlrpc, hotlink protection, compression and caching. Open ›
A user:password entry (APR1-MD5 or SHA-1) to protect directories, wp-admin and staging sites. Password hashed in your browser. Open ›
WordPress rules: block wp-admin, sitemap, limit AI crawlers, block the internal search and custom paths. Open ›
HSTS, Content-Security-Policy, X-Frame-Options and more, in Apache (.htaccess) or Nginx format. Guards against clickjacking and XSS. Open ›
Unique security keys (AUTH_KEY, SALT and the rest) for wp-config.php, randomized in your browser. Ready to paste. Open ›
Single and bulk 301 redirects for Apache and Nginx. Keep your Google rankings after a URL change or migration. Open ›
schema.org structured data: Article, LocalBusiness, FAQPage, Organization and BreadcrumbList. Ready-to-paste JSON-LD for rich results. Open ›
Common wp-config.php constants: debug, memory limit, disabling the file editor, blocking updates, revisions and autosave. Open ›
A pf firewall (pf.conf) for OpenBSD and FreeBSD: scrub, antispoofing, per-service rules, NAT, port forwarding and brute-force protection. Open ›
An nftables or iptables firewall: default drop policy, connection state, SSH with rate limiting, scan and SYN-flood protection. Open ›
We build, maintain and secure WordPress sites and stores. No obligation — a concrete proposal after a short conversation.
VAT ID: PL6391758393