{"id":354246,"date":"2026-09-13T12:30:48","date_gmt":"2026-09-13T12:30:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/bettershield\/"},"modified":"2026-10-05T15:31:41","modified_gmt":"2026-10-05T15:31:41","slug":"bettershield","status":"publish","type":"plugin","link":"https:\/\/lmo.wordpress.org\/plugins\/bettershield\/","author":15786956,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.0","stable_tag":"1.1.0","tested":"7.1.3","requires":"6.7","requires_php":"8.0","requires_plugins":null,"header_name":"BetterShield","header_author":"WPDeveloper","header_description":"Checks your site for security problems and explains what each one really means. Fix what you want. Every fix can be undone.","assets_banners_color":"092a22","last_updated":"2026-10-05 15:31:41","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/bettershield.ai","header_author_uri":"https:\/\/wpdeveloper.com\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":318,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"wpdevteam","date":"2026-09-13 12:30:26","revision":3693641},"1.1.0":{"tag":"1.1.0","author":"wpdevteam","date":"2026-10-05 15:31:41","revision":3729185}},"upgrade_notice":{"1.1.0":"<p>This update adds a built-in MCP server for AI assistants, the optional BetterShield Hub, protection for the comment, password reset and sign-up forms, more audit checks, snoozable findings and a sixteenth one-click fix. Recommended for all sites.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3729390,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3729390,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3729390,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3729390,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.1.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3729185,"resolution":"1","location":"assets","locale":"","width":1200,"height":1554},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3729185,"resolution":"2","location":"assets","locale":"","width":1200,"height":2340},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3729185,"resolution":"3","location":"assets","locale":"","width":1200,"height":2146},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3729185,"resolution":"4","location":"assets","locale":"","width":1200,"height":1818},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3729185,"resolution":"5","location":"assets","locale":"","width":1200,"height":1798},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3729185,"resolution":"6","location":"assets","locale":"","width":1200,"height":1650}},"screenshots":{"1":"The Overview after the first audit: the score, the three fixes worth doing first, and what changed since your last visit.","2":"Every finding with its severity, why it matters, and a fix or a reason to mark it not applicable.","3":"One-click hardening. Each item previews what will change and has an undo that never expires.","4":"Login protection: how the site sees a connection, attempt limits, lockouts, and the addresses always allowed or never allowed.","5":"The activity log: who did what and when, with filters, search and a CSV export.","6":"Files compared against the copies WordPress.org publishes, with the difference shown and one click to put a file back."}},"plugin_section":[262246],"plugin_tags":[9211,8531,31093,1229,600],"plugin_category":[54],"plugin_contributors":[149406],"plugin_business_model":[],"class_list":["post-354246","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-2fa","plugin_tags-activity-log","plugin_tags-hardening","plugin_tags-login-security","plugin_tags-security","plugin_category-security-and-spam-protection","plugin_contributors-wpdevteam","plugin_committers-re_enter_rupok","plugin_committers-wpdevteam"],"banners":{"banner":"https:\/\/ps.w.org\/bettershield\/assets\/banner-772x250.png?rev=3729390","banner_2x":"https:\/\/ps.w.org\/bettershield\/assets\/banner-1544x500.png?rev=3729390","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/bettershield\/assets\/icon-128x128.png?rev=3729390","icon_2x":"https:\/\/ps.w.org\/bettershield\/assets\/icon-256x256.png?rev=3729390","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/bettershield\/assets\/screenshot-1.png?rev=3729185","caption":"The Overview after the first audit: the score, the three fixes worth doing first, and what changed since your last visit."},{"src":"https:\/\/ps.w.org\/bettershield\/assets\/screenshot-2.png?rev=3729185","caption":"Every finding with its severity, why it matters, and a fix or a reason to mark it not applicable."},{"src":"https:\/\/ps.w.org\/bettershield\/assets\/screenshot-3.png?rev=3729185","caption":"One-click hardening. Each item previews what will change and has an undo that never expires."},{"src":"https:\/\/ps.w.org\/bettershield\/assets\/screenshot-4.png?rev=3729185","caption":"Login protection: how the site sees a connection, attempt limits, lockouts, and the addresses always allowed or never allowed."},{"src":"https:\/\/ps.w.org\/bettershield\/assets\/screenshot-5.png?rev=3729185","caption":"The activity log: who did what and when, with filters, search and a CSV export."},{"src":"https:\/\/ps.w.org\/bettershield\/assets\/screenshot-6.png?rev=3729185","caption":"Files compared against the copies WordPress.org publishes, with the difference shown and one click to put a file back."}],"raw_content":"<!--section=description-->\n<p>Most security plugins tell you whether your WordPress site is protected. BetterShield goes a step further: it tells you what it checked and what it found, and fixes the issues for you.<\/p>\n\n<p><strong>BetterShield<\/strong> is a WordPress security plugin by WPDeveloper. It audits your site, explains every finding <strong>in plain language<\/strong>, fixes what it can in one click with your approval, and gives every fix an undo that never expires. Two-factor authentication (2FA), passkeys, login protection, an activity log, incident response, a lockout recovery link and a built-in MCP connector for AI assistants are included. No account and no sign-up needed.<\/p>\n\n<h4>Why site owners choose BetterShield<\/h4>\n\n<ul>\n<li><strong>Finds security problems AND fixes them, with your approval.<\/strong> A <em>54-check audit<\/em> scores your site, and sixteen one-click fixes close the gaps. Nothing changes until you choose a fix.<\/li>\n<li><strong>Every fix has an undo that never expires.<\/strong> Change your mind months later and undo it in one click.<\/li>\n<li><strong>Ask an AI assistant what needs fixing.<\/strong> Claude, ChatGPT, Cursor and other assistants can read your site's security through the built-in MCP server, off until you turn it on.<\/li>\n<li><strong>Every site in one Hub.<\/strong> See and fix every site you look after in one place.<\/li>\n<li><strong>Nothing leaves your site unless you choose it.<\/strong> Out of the box, the only outside services contacted are WordPress.org\u2019s own, asked about your files and plugins. Usage sharing, the leaked-password check, your AI provider and BetterShield Hub are each off until you turn them on.<\/li>\n<li><strong>Honest results.<\/strong> A file that was never compared, or a check that could not run, is never reported as clean.<\/li>\n<li><strong>Performance you can see.<\/strong> The Overview shows the queries and milliseconds BetterShield added to real page views.<\/li>\n<li><strong>The essentials are FREE.<\/strong> The full audit, all 16 fixes with undo, 2FA, passkeys, the activity log, the file integrity check and alerts.<\/li>\n<\/ul>\n\n<h4>Quick Setup<\/h4>\n\n<p>A short Quick Setup Wizard opens once after activation. It offers <strong>5 hardening fixes<\/strong> that cannot lock anyone out, makes sure you have a way back in (a <strong>single-use recovery link<\/strong> emailed to the admin address, plus printable recovery codes), and lets you choose which plugin handles which job if another security plugin is active. Skip it, or run it again from Settings &gt; General.<\/p>\n\n<h4>WordPress Security Audit: 54 checks that act when you approve<\/h4>\n\n<p>Fifty-four read-only checks cover access, exposure, updates, extensions, server settings and configuration, including:<\/p>\n\n<ul>\n<li>Idle \u201cAdmin\u201d accounts nobody has used in over six months<\/li>\n<li>User enumeration, XML-RPC, the file editor and the WordPress version on every page<\/li>\n<li>Missing security headers, an outdated PHP version and weak security keys<\/li>\n<li>Plugins closed on WordPress.org, or with no update for years<\/li>\n<li>Installer or database tools left in the web root after a migration<\/li>\n<li>A domain without SPF, DMARC or CAA records<\/li>\n<li>Core and plugin files that no longer match the official copies<\/li>\n<\/ul>\n\n<p>Each finding explains what it is, why it matters and what could break if you act on it. Not ready yet? Snooze it for 7 or 30 days.<\/p>\n\n<h4>One-click hardening: 16 fixes, each with a permanent undo<\/h4>\n\n<p>Each fix shows what it will change before you apply it and stays off until you do. A fix your hosting cannot support, such as .htaccess rules on a server that is not Apache, cannot be switched on, and the screen tells you why.<\/p>\n\n<p>The sixteen one-click fixes:<\/p>\n\n<ul>\n<li>Disable XML-RPC<\/li>\n<li>Disable the dashboard file editor<\/li>\n<li>Block public user listing (user enumeration)<\/li>\n<li>Stop PHP running in uploads<\/li>\n<li>Stop uploads directories listing their contents<\/li>\n<li>Hide sensitive files from visitors<\/li>\n<li>Change the sign-in address (custom login URL)<\/li>\n<li>Refuse application passwords<\/li>\n<li>Refuse passwords found in known breaches<\/li>\n<li>Keep low-privilege accounts out of the dashboard<\/li>\n<li>Hide the dashboard from visitors<\/li>\n<li>Stop publishing the WordPress version<\/li>\n<li>Strengthen and rotate the sign-in keys<\/li>\n<li>Tell browsers to refuse plain HTTP (HSTS)<\/li>\n<li>Find out what a content security policy (CSP) would break, before you enforce one<\/li>\n<li>Send security response headers<\/li>\n<\/ul>\n\n<h4>AI explanations and AI assistants (MCP)<\/h4>\n\n<ul>\n<li>With an AI provider connected under Settings &gt; Connectors (WordPress 7.0 or newer), explain any finding in plain language, or ask Explain my audit for a summary.<\/li>\n<li>The MCP server lets Claude, ChatGPT, Cursor, Codex and other assistants read your site's security through eighteen bounded, read-only abilities. It is off until you turn it on under <strong>Agents &gt; Connect.<\/strong><\/li>\n<li>A second switch, off by default, lets an assistant apply and undo fixes.<\/li>\n<li><strong>Never possible through a connection:<\/strong> creating accounts or credentials, changing recovery, two-factor or alert settings, lifting lockouts, or deleting log rows.<\/li>\n<\/ul>\n\n<h4>Using BetterShield with another security plugin<\/h4>\n\n<p>BetterShield works alongside the security plugin you already have, and makes sure the two do not do the same job twice. Switching over completely? It can bring over settings from Kadence Security, All-In-One Security, Really Simple Security or Wordfence, with a preview first and an undo.<\/p>\n\n<h4>Two-factor authentication (2FA) and passkeys<\/h4>\n\n<p>For yourself, the roles you choose or your WooCommerce customers:<\/p>\n\n<ul>\n<li><strong>Two-factor with any authenticator app<\/strong> and ten single-use backup codes, never enforced until the app is proven to work.<\/li>\n<li><strong>Require two-factor by role<\/strong>, with a 14-day grace period by default.<\/li>\n<li><strong>Passkeys:<\/strong> sign in with a fingerprint, face or device PIN. Only the public half of the key is stored.<\/li>\n<li><strong>Passkey-only sign-in by role,<\/strong> once a working recovery option is in place.<\/li>\n<\/ul>\n\n<h4>Login protection and brute force defense<\/h4>\n\n<ul>\n<li><strong>Limit login attempts:<\/strong> by default, 5 failed sign-ins in 15 minutes pause that connection for 15 minutes, doubling with each repeat within a day.<\/li>\n<li><strong>A hidden bot check<\/strong> on the login, registration, WooCommerce account and comment forms.<\/li>\n<li><strong>Limits on public forms:<\/strong> comment bursts wait in moderation, and repeated password resets or sign-ups are paused.<\/li>\n<li><strong>Strong password rules<\/strong>, an optional leaked-password check, an IP and username blocklist, and an allowlist that is never locked out.<\/li>\n<\/ul>\n\n<h4>Lockout recovery<\/h4>\n\n<p>Locked out? Get back in without FTP or a call to your host. A single-use recovery link, emailed when you activate BetterShield, pauses its sign-in protections for one hour and leaves your settings as they are. Printed recovery codes are a second way in.<\/p>\n\n<h4>Security activity log<\/h4>\n\n<p>Sign-ins, account and role changes, password resets, and plugin, theme and core changes, with who and when. <strong>Filter, search and export to CSV, with 30 days of history.<\/strong> Each finished day is sealed, so an edit or deletion opens a high-severity finding.<\/p>\n\n<h4>Incident response<\/h4>\n\n<p>Related access and file changes are joined into one incident, with signs of an account takeover flagged. You review the response plan before anything changes, and BetterShield checks again afterwards.<\/p>\n\n<h4>Security alerts<\/h4>\n\n<p><strong>A weekly summary that arrives on quiet weeks too,<\/strong> and high or critical events emailed on their own. No message ever contains an upgrade prompt.<\/p>\n\n<h4>File integrity check against WordPress.org<\/h4>\n\n<p>WordPress core and directory plugins are compared with the official copies WordPress.org publishes, showing exactly which lines changed. One click puts the official file back, and the replaced file is kept, never deleted. Your theme, drop-ins, wp-config.php, .htaccess and other unpublished code are watched for changes.<\/p>\n\n<h4>BetterShield Hub (Multisite Control)<\/h4>\n\n<p>An optional dashboard for people who look after more than one site. Connect sites from BetterShield &gt; Hub to see every score and finding in one place, apply or undo fixes across sites with nothing changing until you agree, get alerts when a site goes down or its grade drops, and invite your team. Everything in BetterShield works without the hub.<\/p>\n\n<h4>Built for agencies and many sites<\/h4>\n\n<ul>\n<li>WP-CLI commands for audits, findings, hardening, activity, recovery, file checks and settings<\/li>\n<li>Settings export and import, with a preview and an undo<\/li>\n<li>Multisite: every site's score in one table, and two-factor and passkey rules set once for the network<\/li>\n<\/ul>\n\n<h4>BetterShield Ultra [Pro]<\/h4>\n\n<p>Ultra is a separate paid add-on for people who look after sites for others. It needs the free plugin and is not on sale yet. It will add:<\/p>\n\n<ul>\n<li>Two-factor set-up at sign-in for the roles you choose<\/li>\n<li>Trusted devices and a sign-in report by role<\/li>\n<li>Branded two-factor screens<\/li>\n<li>Slack and webhook alerts<\/li>\n<li>A scheduled client report<\/li>\n<li>Temporary access that ends on its own<\/li>\n<\/ul>\n\n<h3>Backed By a Team You Trust<\/h3>\n\n<p>BetterShield is developed by the trusted team at <strong><a href=\"https:\/\/wpdeveloper.com\/\">WPDeveloper<\/a>,<\/strong> a leading WordPress product company used and loved by 6 million users and businesses.<\/p>\n\n<h3>External services<\/h3>\n\n<p>BetterShield contacts six outside addresses, and a seventh, BetterShield Hub, reaches it only if you connect the site to the hub. It contacts four addresses operated by WordPress.org, all to check that your files still match the official ones and to put an official file back if you ask. It contacts your own AI provider only if you have connected one, the Pwned Passwords service only if you switch on the breached-password check, and the usage service only if you choose to share usage data.<\/p>\n\n<p><strong>api.wordpress.org<\/strong> \u2014 the published checksums for your WordPress version, when the file check runs on its schedule or when you start one; the request carries your WordPress version and language. Once a day it also asks whether the directory still lists a few of the plugins you installed from it; that request carries the plugin's slug only. Plugins you choose to install in the Quick Setup's optional last step are fetched by WordPress's own installer, from here and downloads.wordpress.org.<\/p>\n\n<p><strong>downloads.wordpress.org<\/strong> \u2014 the published checksums for a directory plugin at the exact version you have, during the same check and whenever a plugin is installed or updated, including automatic updates. The request carries the plugin's slug and version.<\/p>\n\n<p><strong>core.svn.wordpress.org<\/strong> and <strong>plugins.svn.wordpress.org<\/strong> \u2014 the official copy of one file, fetched only when you press Restore on a changed file. The request carries the version and the file's path, and the copy is checked against the published checksum before anything is written.<\/p>\n\n<p><strong>api.pwnedpasswords.com<\/strong> \u2014 the Pwned Passwords service by Have I Been Pwned, only if you switch on \u201cRefuse passwords found in known breaches\u201d, and only when someone signed in to your site sets or changes a password. The password is hashed on your server and only the first five characters of the hash are sent; the comparison happens on your server. No password, account name, email, site address or identifier is sent. Documentation: https:\/\/haveibeenpwned.com\/API\/v3#PwnedPasswords \u2014 privacy policy: https:\/\/haveibeenpwned.com\/Privacy<\/p>\n\n<p><strong>send.wpinsight.com<\/strong> \u2014 WPDeveloper's usage service, only if you choose to share usage data (Get Started on the first Quick Setup step; Skip sends nothing). At most once a day, and once when you deactivate BetterShield, it sends your site address and title, administrator email, WordPress, PHP and web server versions, language settings, whether the site is multisite, the installed and active plugins, your theme and its version, BetterShield's version and folder name, and the report reference. Never anything about your visitors, users, sign-ins or findings. Turn it off under Settings &gt; General. Privacy policy: https:\/\/wpdeveloper.com\/privacy-policy<\/p>\n\n<p><strong>BetterShield Hub<\/strong> (hub.bettershield.ai, or the address you set under BetterShield &gt; Hub), only if you connect the site and approve it on this site's own consent page. The hub then reads the score, findings and available tools, and applies or removes a protection when you ask, under the same rules as an AI assistant. This site does not contact the hub; the hub contacts the site and checks every few minutes that its front page answers. Disconnect ends it at once.<\/p>\n\n<p><strong>Your own AI provider<\/strong>, only if you have connected one to WordPress and only when you ask for an explanation. WordPress sends the request through your connector under Settings &gt; Connectors; BetterShield never sees, asks for or stores the key. It sends the finding's title, severity, description and recorded evidence, with web and email addresses stripped, and never file contents, usernames, keys or your site's address.<\/p>\n\n<p>None of the WordPress.org requests carries anything about your site: no site address, email, username, IP address, keys, file contents or identifier. They happen on a schedule, when you press a button, or when a plugin is installed or updated, never while a visitor loads a page. If a service cannot be reached, the check says it could not run rather than reporting a file as unchanged.<\/p>\n\n<p>The four WordPress.org addresses are provided by the WordPress Foundation. Terms of use: https:\/\/wordpress.org\/about\/privacy\/ and https:\/\/wordpress.org\/about\/privacy\/cookies\/<\/p>\n\n<p><strong>Published vulnerability advisories<\/strong> \u2014 not contacted in this version. No data source is connected, and the Findings screen says so. When one is, this section will name it and say what is sent, and the check will stay off until you turn it on.<\/p>\n\n<h3>What it keeps about people<\/h3>\n\n<p>Everything BetterShield keeps about a person stays on your own server: activity log rows, sign-in attempts, passkeys and account records, with IP addresses truncated to a network before they are stored. The FAQ above describes each record. Tools &gt; Export Personal Data and Tools &gt; Erase Personal Data both support BetterShield, and Tools &gt; Site Health &gt; Info lists every record, why it is kept and for how long.<\/p>\n\n<h3>Source code<\/h3>\n\n<p>Everything that runs is readable in the plugin folder. The PHP in <code>src\/<\/code> is not generated, compiled or minified. The admin interface is compiled into <code>assets\/build\/<\/code> (scripts, stylesheets and small generated PHP files that list each script's dependencies) from the sources in <code>assets\/js\/<\/code> and <code>assets\/css\/<\/code>, which ship next to it. To rebuild, run <code>npm install<\/code> and then <code>npm run build<\/code>, which uses @wordpress\/scripts from the included <code>package.json<\/code>.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>In your dashboard, go to Plugins &gt; Add Plugin, search for \"BetterShield\", then install and activate it. Or upload the folder to <code>\/wp-content\/plugins\/bettershield<\/code>.<\/li>\n<li>On activation, a read-only security audit runs, your recovery link is emailed to the site's admin address, and the Quick Setup opens.<\/li>\n<li>Open <strong>BetterShield<\/strong> in the admin menu to see your score and findings.<\/li>\n<\/ol>\n\n<p>No hardening fix, required two-factor or passkey-only sign-in is switched on <strong>until you choose it.<\/strong> A few protections start at activation, and each can be switched off:<\/p>\n\n<ul>\n<li>Login attempt limits<\/li>\n<li>A hidden bot check on the login, registration, WooCommerce account and comment forms<\/li>\n<li>Limits on the comment, password reset and sign-up forms<\/li>\n<li>Minimum password lengths<\/li>\n<li>Weekly and instant email alerts<\/li>\n<\/ul>\n\n<!--section=faq-->\n<dl>\n<dt id=\"is%20bettershield%20free%3F\"><h3>Is BetterShield free?<\/h3><\/dt>\n<dd><p>Yes. The audit, every plain-language explanation, all 16 fixes and their undo, two-factor authentication, passkeys, login protection, the recovery link, the activity log, incident response, the file check and the MCP server are free. There is no account and no payment. BetterShield Ultra, a separate add-on for agencies, is coming soon and adds extras such as AI client drafts, a network-wide Incidents tab and longer history.<\/p><\/dd>\n<dt id=\"does%20bettershield%20include%20a%20firewall%20or%20malware%20scanner%3F\"><h3>Does BetterShield include a firewall or malware scanner?<\/h3><\/dt>\n<dd><p>No. BetterShield does not include a firewall and does not scan for or remove malware. It audits your configuration, hardens it with fixes you can undo, secures logins, logs activity, groups suspicious changes into incidents, compares WordPress core and directory plugins with the official WordPress.org copies, and watches your theme and the files nobody publishes for changes.<\/p><\/dd>\n<dt id=\"can%20i%20use%20bettershield%20alongside%20another%20security%20plugin%3F\"><h3>Can I use BetterShield alongside another security plugin?<\/h3><\/dt>\n<dd><p>Yes, with care. If another security plugin is active, the Quick Setup asks which plugin should keep each shared job, such as login limits, so they are not both doing it. On the Hardening screen, a fix another plugin already covers says so. It does not catch every overlap, so check the other plugin's settings too, and avoid turning on login or two-factor features in both.<\/p><\/dd>\n<dt id=\"how%20do%20i%20switch%20from%20another%20security%20plugin%3F\"><h3>How do I switch from another security plugin?<\/h3><\/dt>\n<dd><p>Install BetterShield and let the first audit run; it changes nothing. If you are coming from Kadence Security, All-In-One Security, Really Simple Security or Wordfence, Settings &gt; General can bring over their protections and sign-in attempt limits. You see a preview first, it lists what it could not carry and why, the other plugin is only read, and the import can be undone. Then apply any other fixes you want one at a time and switch the old plugin's features off as you go.<\/p><\/dd>\n<dt id=\"will%20the%20fixes%20break%20my%20site%3F\"><h3>Will the fixes break my site?<\/h3><\/dt>\n<dd><p>Every fix can show you what it will change before you apply it, and each can be undone at any time. Where an undo cannot reach everything, the fix says so first: people signed out by a key change stay signed out, and browsers that already saw the HSTS header keep insisting on HTTPS until it expires.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20lock%20myself%20out%3F\"><h3>What happens if I lock myself out?<\/h3><\/dt>\n<dd><p>Open your latest recovery link and press its one button. BetterShield's sign-in protections pause for one hour and your settings stay exactly as they are. You can generate a fresh link from Protect &gt; Recovery at any time; generating one stops the old one working. Using a link issues the next one straight away, on the page and by email. A link you never use stops working after 90 days, and BetterShield warns you in the last two weeks. Printed recovery codes are a second way back in.<\/p><\/dd>\n<dt id=\"can%20two-factor%20authentication%20lock%20my%20users%20out%3F\"><h3>Can two-factor authentication lock my users out?<\/h3><\/dt>\n<dd><p>Not by setting it up. Nothing is enforced until the app is proven to work and the backup codes are saved, and required two-factor comes with a grace period (14 days by default). If someone loses their phone, a backup code signs them in, and an administrator can turn two-factor off for them.<\/p><\/dd>\n<dt id=\"will%20it%20slow%20down%20my%20site%3F\"><h3>Will it slow down my site?<\/h3><\/dt>\n<dd><p>The Overview measures it and shows the number for your own site. For visitors, BetterShield runs the fixes you turned on, its login protection on sign-in, the limits on the comment, reset and sign-up forms, and a hidden bot check on the sign-in, registration and comment forms. Audits, file checks and emails never run inside a visitor's page view. On the WooCommerce cart and checkout, BetterShield adds no bot check, skips its sampling, checks and housekeeping, and only records security events.<\/p><\/dd>\n<dt id=\"does%20it%20send%20my%20data%20anywhere%3F%20do%20i%20need%20an%20account%3F\"><h3>Does it send my data anywhere? Do I need an account?<\/h3><\/dt>\n<dd><p>There is no account. Out of the box, BetterShield contacts WordPress.org only, to check your files and plugins, and those requests carry version numbers and plugin slugs, never your site address, email or username. Everything else is off until you turn it on: usage sharing (the first Quick Setup step), the leaked-password check, your own AI provider, and BetterShield Hub. External services below lists exactly what each one sends.<\/p><\/dd>\n<dt id=\"what%20does%20bettershield%20keep%20about%20people%3F\"><h3>What does BetterShield keep about people?<\/h3><\/dt>\n<dd><p>Everything is stored on your own server. The main records:<\/p>\n\n<ul>\n<li><strong>Activity log:<\/strong> what happened and who did it, with IP addresses truncated to a network before storage. Rows are removed after thirty days.<\/li>\n<li><strong>Sign-in attempts:<\/strong> the username tried, the outcome, the truncated network and a keyed digest of the IP address, used for lockout decisions and pruned aggressively.<\/li>\n<li><strong>Passkeys:<\/strong> the device name you gave, when it was added and when it was last used. Only the public half of the key is stored.<\/li>\n<li><strong>Account records:<\/strong> two-factor setup, backup codes, password-policy status, two-factor deadlines and last sign-in.<\/li>\n<\/ul>\n\n<p>Tools &gt; Export Personal Data and Tools &gt; Erase Personal Data both support BetterShield. A few security records are kept on purpose, and the erasure result says so: the date the account last signed in, lockout records, incident evidence and assistant activity. Tools &gt; Site Health &gt; Info lists every record, how long it is kept, and what erasure does to it.<\/p><\/dd>\n<dt id=\"does%20bettershield%20detect%20vulnerable%20plugins%3F\"><h3>Does BetterShield detect vulnerable plugins?<\/h3><\/dt>\n<dd><p>Not yet. The check against published vulnerability advisories is built, but no data source is connected in this version, and the Findings screen says so rather than showing an empty list as a clean result. Today BetterShield flags plugins the WordPress.org directory has closed or that have had no update for years, and its file check shows any core or directory plugin file that no longer matches the official copy.<\/p><\/dd>\n<dt id=\"is%20the%20activity%20log%20tamper-proof%3F\"><h3>Is the activity log tamper-proof?<\/h3><\/dt>\n<dd><p>No, and it does not claim to be. It is tamper-evident: each finished day is sealed and chained to the day before. If a sealed day is later edited or deleted, the next daily check opens a high-severity finding.<\/p><\/dd>\n<dt id=\"can%20an%20ai%20assistant%20change%20my%20site%3F\"><h3>Can an AI assistant change my site?<\/h3><\/dt>\n<dd><p>Only if you let it. The MCP connection is off until you turn it on under Agents &gt; Connect, and reading and changing are separate switches. With only reading on, an assistant can look and change nothing. With changing on, it can apply and undo fixes and put a changed file back, and every change has an undo and is recorded in the activity log. A connection can be issued read-only whatever the switches say. Creating accounts or credentials, changing your recovery options, two-factor or alert settings, lifting lockouts and deleting log rows are never possible through a connection. Agents &gt; Surface shows which abilities on your site, from any plugin, can make changes.<\/p><\/dd>\n<dt id=\"do%20i%20need%20bettershield%20hub%3F\"><h3>Do I need BetterShield Hub?<\/h3><\/dt>\n<dd><p>No. It is optional, and everything in the plugin works without it. The hub is for people who look after several sites and want their scores, findings and fixes in one place. You connect each site from its own BetterShield &gt; Hub screen and approve it on that site. To end the connection, press Disconnect on the site: removing a site inside the hub does not end it.<\/p><\/dd>\n<dt id=\"what%20can%20bettershield%20hub%20see%20and%20change%3F\"><h3>What can BetterShield Hub see and change?<\/h3><\/dt>\n<dd><p>What you allow when you connect. Read-only lets it see the score, findings and a few security views, such as administrators by display name and role. Read-and-fix also lets it apply and undo fixes; each change shows the site's own plan first and waits for someone in your hub team to agree. Connecting turns on the plugin's assistant connection if it is off, and the consent page has \"Allow it to change this site\" ticked by default, so untick it if you want read-only. Every change the hub makes is recorded in the site's activity log.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20woocommerce%3F\"><h3>Does it work with WooCommerce?<\/h3><\/dt>\n<dd><p>Yes. Customers can set up two-factor, add passkeys and see where they are signed in from a Sign-in security tab on My Account. BetterShield adds nothing to the cart or checkout pages.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20multisite%3F\"><h3>Does it work on multisite?<\/h3><\/dt>\n<dd><p>Yes. Each site keeps its own findings, settings and fixes. The network admin gets every site's score and open findings in one table, 200 sites at a time, two-factor and passkey rules set once as a floor under every site, and a recovery link for the network.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20delete%20the%20plugin%3F\"><h3>What happens if I delete the plugin?<\/h3><\/dt>\n<dd><p>Its records stay by default, including the activity log, findings and undo history, so reinstalling picks up where you left off. Fixes it applied, including .htaccess rules, stay applied too, so undo anything you do not want to keep before you delete. Under Settings &gt; General, \"If this plugin is ever deleted\" can instead remove this plugin's records, which also takes its server rules back off.<\/p>\n\n<p>Copies of files it replaced are kept in <code>wp-content\/uploads\/bettershield-quarantine\/<\/code>, because the version that was there may be exactly what somebody put on your site, and deleting it on the way out is not a decision this plugin makes for you. Remove them one at a time from Activity &gt; Files before you delete the plugin, or delete the folder yourself afterwards. A third setting does both for you: it packages the copies into one zip file inside <code>wp-content\/uploads\/bettershield-quarantine\/<\/code>, takes the copies away only once that archive has been written, and then removes this plugin's records as above. Nothing serves that archive, since the folder it is written into refuses to hand anything out, so collect it the way you would any other file on the site, over SFTP or from your host's file manager.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.0 - 05\/10\/2026<\/h4>\n\n<ul>\n<li>Added: Usage Data | Optional usage data sharing, asked once in Quick Setup and switchable under Settings &gt; General<\/li>\n<li>Added: Overview | See which checks opened, passed, changed severity or were marked not applicable since an earlier day, with the score then and now<\/li>\n<li>Added: Security Audit | Four new checks: unfiltered code below administrator, script uploads below administrator, this plugin's automatic updates switched off, and world-writable folders under wp-content<\/li>\n<li>Added: Recovery | Checks that a recovery link or printed code works before any change to how people sign in, from the dashboard or <code>wp bettershield harden<\/code> (<code>--force<\/code> to go ahead)<\/li>\n<li>Added: Incidents | An email change, a password change and a new application password on one privileged account within an hour are recorded together as one high signal<\/li>\n<li>Added: Incident Response | Re-checks the site after a response runs and lists what is still open<\/li>\n<li>Added: Overview | Notes when failed sign-ins or the scheduler's timing are far outside this site's last 30 days<\/li>\n<li>Added: AI Explanations | Explain my audit summarizes the open findings in three short paragraphs that cite each finding<\/li>\n<li>Added: Settings Import | Bring over protections and sign-in attempt limits from another security plugin, with a preview and an undo<\/li>\n<li>Added: MCP Server | Connect Claude, ChatGPT or any MCP assistant to read the audit, activity and file check, apply fixes you can undo and restore changed files, with every call logged<\/li>\n<li>Added: Agents | A new Agents section with Connect, Requests, Permissions and Surface tabs<\/li>\n<li>Added: BetterShield Hub | Optional hub connection from BetterShield &gt; Hub, Settings or the end of Quick Setup, approved once on the site's own consent page<\/li>\n<li>Added: Overview | A storage card that names a missing database table or column and offers a Repair<\/li>\n<li>Added: Uninstall | A third choice when deleting the plugin: pack the quarantined copies into one archive, then remove them<\/li>\n<li>Added: Hardening | A sixteenth fix: refuse new passwords found in known breaches, off by default<\/li>\n<li>Added: File Integrity | Reports a new .user.ini file that appears after the site's configuration was recorded<\/li>\n<li>Added: Security Audit | Names PHP files and folders in the plugins folder that no installed plugin claims<\/li>\n<li>Added: Security Audit | Flags directory plugins with no update for two years, with the last-updated date<\/li>\n<li>Added: Form Protection | Comment bursts are held for moderation, and repeated password resets and sign-ups from one connection are paused<\/li>\n<li>Added: WooCommerce | Customers manage two-factor, passkeys and signed-in devices from a Sign-in security tab on My Account<\/li>\n<li>Added: Login Protection | Block a username from signing in<\/li>\n<li>Added: Security Audit | Finds installer and database tools left in the web root, with quarantine from the finding<\/li>\n<li>Added: Security Audit | Checks whether admin-ajax shares signed-in answers with other websites, and names where the policy was widened<\/li>\n<li>Added: Security Audit | Detects a sign-in page served by a page cache or CDN<\/li>\n<li>Added: Security Audit | Checks the domain's SPF, DMARC and CAA records once a day<\/li>\n<li>Added: Security Audit | Warns when free disk space runs low<\/li>\n<li>Added: Findings | Snooze a finding for 7 or 30 days, with its own Snoozed filter and <code>wp bettershield findings --status=snoozed<\/code><\/li>\n<li>Added: Plugins Screen | Add New shows whether a plugin is closed on WordPress.org or has had no update for two years<\/li>\n<li>Added: Application Passwords | Limit an application password to its REST routes, its network, or both, from Agents &gt; Surface<\/li>\n<li>Added: Site Moves | When the site address or folder changes, the Overview asks whether it is a staging copy or a move, with one undo<\/li>\n<li>Added: Incident Response | Ask a privileged account for a new password, with an undo<\/li>\n<li>Improved: Quick Setup | Previews what each fix will do before applying it, leaves risky fixes unticked, and undoes the applied set in one step<\/li>\n<li>Improved: Request Protection | Each public form has its own threshold, window and closing time, with a replay of the last two days before you save<\/li>\n<li>Improved: Incidents | Evidence names each row's network and links to the activity log for the incident's days<\/li>\n<li>Improved: Activity Log | Open everything from one person or one network from any log row, and narrow agent activity to one account<\/li>\n<li>Improved: Multisite | The network overview shows how many sites it lists and loads more on request on networks of more than 200 sites<\/li>\n<li>Improved: Privacy | Add-ons can declare a per-site personal data record so the privacy export finds it<\/li>\n<li>Improved: Audit | Says how many checks could be evaluated when a run could not check them all, and marks findings kept from an earlier run<\/li>\n<li>Improved: File Integrity | A changed file too long to compare whole shows the part that changed<\/li>\n<li>Improved: File Integrity | A plugin copy you reviewed and adopted stays quiet until it changes again<\/li>\n<li>Improved: Login Protection | Repeat lockouts within a day double in length, up to one day<\/li>\n<li>Improved: Compatibility | Recognizes one more security plugin, so the same job is not done twice<\/li>\n<li>Improved: Settings Import | Brings over sign-in attempt limits, allowed addresses, the breached-password check, username discovery block, version hiding and uploads protection from one more security plugin<\/li>\n<li>Improved: Settings Export | Blocked usernames are included in an exported settings file<\/li>\n<li>Improved: File Integrity | The Files screen groups changes by plugin and version, with Check again and Mark all expected (<code>wp bettershield integrity recheck<\/code> and <code>expect<\/code>)<\/li>\n<li>Improved: Activity Log | Notes which code files an update to a plugin outside the directory added or changed<\/li>\n<li>Improved: Alerts | Connecting an assistant, rotating its credential or approving an app sends an instant alert<\/li>\n<li>Improved: Hardening | The usage preview on the XML-RPC and application password fixes looks back across the whole activity record<\/li>\n<li>Improved: Admin Menu | The sidebar shows the BetterShield icon<\/li>\n<li>Improved: Confirmations | Applying an incident response, disabling the decoy URL and withdrawing an agent's confirmation ask once more before acting<\/li>\n<li>Improved: Agents | A credential connected while agents may not change the site is issued read-only<\/li>\n<li>Fixed: Login Protection | Sign-in lockouts keep working right after an update, before the database is upgraded<\/li>\n<li>Fixed: Login Protection | Lockouts stand down behind a proxy that forwards no visitor address, instead of locking all visitors out together<\/li>\n<li>Fixed: Multisite | On installs with more than one network, the network dashboard and activity log show only that network's sites<\/li>\n<li>Fixed: Hardening | A protection set to applied while safe mode is on is shown as paused<\/li>\n<li>Fixed: WP-CLI | The agent-activity export carries every matching row, or says where it stopped<\/li>\n<\/ul>\n\n<h4>1.0.0 - 13\/09\/2026<\/h4>\n\n<ul>\n<li>First public release<\/li>\n<li>Added: Security Audit | 40 read-only checks, a score that shows its workings and a plain-language explanation of every finding<\/li>\n<li>Added: Hardening | 15 one-click fixes, each showing what it will change first, each with an undo that never expires<\/li>\n<li>Added: Two-Factor Authentication | Any authenticator app, 10 single-use backup codes, and passkeys<\/li>\n<li>Added: Login Protection | Lockouts after repeated wrong passwords, an allowlist and a blocklist, session limits and an optional idle timeout<\/li>\n<li>Added: Recovery | A recovery link, safe mode and printed offline codes, with daily readiness checks and optional weekly email tests<\/li>\n<li>Added: Activity Log | Sign-ins, accounts, roles, plugins, themes and the plugin's own actions, with filters, search, CSV export and a daily seal<\/li>\n<li>Added: File Integrity | Core and directory-plugin files compared with the copies WordPress.org publishes, with the difference shown and one click to restore a file<\/li>\n<li>Added: Alerts | A weekly email summary that arrives on quiet weeks too, and high and critical events sent on their own<\/li>\n<li>Added: Tools | WP-CLI commands, settings export and import, findings in Site Health, a dashboard widget, and a report of what connected agents can do<\/li>\n<li>Added: Multisite | Every site's score in one table and rules a network can set once<\/li>\n<\/ul>","raw_excerpt":"Free WordPress security audit, sixteen one-click fixes you can undo, 2FA, passkeys, login protection and an activity log. No account needed.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/354246","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=354246"}],"author":[{"embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/wpdevteam"}],"wp:attachment":[{"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=354246"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=354246"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=354246"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=354246"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=354246"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/lmo.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=354246"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}