The wp-config Trio
The Hardening module's toggles live in the database and flip from the admin. Three of the most important hardening measures can't, because they have to be in place before WordPress finishes loading, and because they constrain the admin itself. They're constants in wp-config.php, and the module's status card simply checks whether you've set them.
DISALLOW_FILE_EDIT
By default, any administrator can edit plugin and PHP files right from the dashboard, under Appearance or Plugins, then Editor. That's a convenience with a dark side: an attacker who compromises an admin session doesn't need to upload anything. They paste a web shell into a plugin file using the interface WordPress provided, and now they live in your site.
Adding this line removes those editors entirely:
define( 'DISALLOW_FILE_EDIT', true );
Almost nobody edits plugins through the dashboard on purpose, and those who do shouldn't. This is the closest thing to a free win in WordPress security.
DISALLOW_FILE_MODS
One step further: it disables plugin and theme installation and updates from the admin entirely. Deployments move to SFTP, git, or WP-CLI, which is how serious sites do it anyway.
define( 'DISALLOW_FILE_MODS', true );
The trade is workflow. If you or a client routinely install plugins from the dashboard, this will feel like a wall. On a stable membership site where the plugin list changes twice a year under change control, it removes an entire category of "someone installed something" incidents, including supply-chain surprises from a compromised admin session.
A side effect worth knowing: with file mods disabled, WordPress can no longer auto-update itself or plugins, so patching becomes your job. Run updates deliberately, on a schedule, and this constant is a net win.
FORCE_SSL_ADMIN
Sends every admin session over HTTPS and refuses login cookies on plain HTTP. On any site built in the last decade your admin is probably already HTTPS, because your host forced it. This constant makes it a rule rather than a habit, which matters the day a staging copy, a migration, or a misconfigured proxy serves the admin over HTTP and a login cookie crosses the network in the clear.
define( 'FORCE_SSL_ADMIN', true );
Your whole site should be HTTPS regardless; this extends the guarantee specifically to the admin session, where the valuable cookies live.
Setting them
Edit wp-config.php in the site root, above the line that says "That's all, stop editing." Each constant takes effect on the next page load. The Hardening module's Server Configuration Status card will flip each check to green as it finds them, which is a nice confirmation that the file edit landed.
If you deploy with git and your wp-config.php is managed, put the constants in the environment-specific include rather than the repo copy, and never commit credentials along the way.