Security audit and score
54 read-only checks, a score that shows its workings, and a plain-language explanation of every finding. Not ready for one yet? Snooze it for 7 or 30 days.
BetterShield runs 54 security checks on your site, shows you exactly what is at risk in plain language, and fixes what it can in one click, with your approval. Each fix shows what it will change first, and you can switch it off again.
Example audit: security score 86 out of 100. Two findings fixed, one waiting for review.
Disable XML-RPC
BetterShield inside your dashboard, screen by screen.
Security score
58 Grade D
54 checks · 9 open findings
54 read-only checks across access, exposure, updates, server and configuration. Each finding says what it is, why it matters and what acting on it could break.
Score and findings guideHardening
16 fixes · each previewed before it applies
Dashboard file editor disabled. Undo
16 fixes, each previewed before anything changes. Switching one off removes what it wrote, and the two that cannot reach everything, new sign-in keys and a long HSTS setting, say so first.
Hardening guideBy default, 5 failed sign-ins in 15 minutes pause that connection for 15 minutes. Two-factor works with any authenticator app, passkeys sign people in with a fingerprint, face or device PIN, and you can require two-factor by role.
Login and access guideRecovery
Checked every day, ready when you need it
Printed recovery codes · 2 used
A single-use recovery link by email, or a printed recovery code, pauses the sign-in protections for one hour while you put things right. No FTP, no call to your host.
Locked-out guideSite activity
Today · 4 events
Sign-ins, accounts, roles, plugins, themes and core, with who and when, searchable and kept 30 days. Each finished day is sealed, so an edit or deletion shows up as a finding.
Activity log guideRequests
Changes an assistant has worked out, waiting for you
Change the sign-in address
Claude, ChatGPT or another assistant reads your site’s security over MCP. Fixes that switch off cleanly can apply straight away; anything heavier arrives as a plan you agree to.
Connect an AI assistantMost security plugins tell you whether your site is protected. BetterShield tells you what it checked and what it found, and fixes what it can, with your approval.
The audit, the fixes and everything around them. No account, no payment.
54 read-only checks, a score that shows its workings, and a plain-language explanation of every finding. Not ready for one yet? Snooze it for 7 or 30 days.
16 fixes, each showing what it will change first. Every one has an undo that never expires.
Repeated failed sign-ins pause that connection, with an allowlist, a blocklist and a hidden bot check on the forms.
Any authenticator app with 10 single-use backup codes, and passkeys with a fingerprint, face or device PIN. Require them by role.
A single-use recovery link and printed recovery codes get you back in without FTP or a call to your host.
Sign-ins, accounts, roles, plugins, themes and core, with who and when. Each finished day is sealed, so a later edit or deletion opens a finding.
WordPress core and directory plugins compared with the copies WordPress.org publishes, showing exactly which lines changed. One click puts the official file back, and the replaced file is kept, never deleted.
The check against published vulnerability advisories is built, but no data source is connected in this version. The Findings screen says so, rather than showing an empty list as a clean result.
Related access and file changes are joined into one incident, with signs of an account takeover flagged. You review the response plan before anything changes.
BetterShield keeps each day’s score, so the Overview can show which checks opened, passed or changed severity since an earlier day, with the score then and now.
Turn on the built-in MCP server and Claude, ChatGPT, Cursor, Codex or another assistant can read your site’s security through 18 bounded, read-only abilities.
Changing is a second switch, off by default. With it on, an assistant can apply and undo fixes, and every change is recorded in the activity log. A change to how people sign in, or taking a protection off, waits for you to agree.
Never possible through a connection: creating accounts or credentials, changing recovery, two-factor or alert settings, lifting lockouts, or deleting log rows.
What should I fix first?
Used Read the audit → score 58 · 9 open findings
Start with the dashboard file editor. Turning it off is a one-click fix with an undo, so I can do that now. Changing the sign-in address needs your agreement first.
Used Apply a fix → Disable the dashboard file editor · undo kept
A paid add-on for people who look after sites for others: two-factor setup at sign-in, trusted devices, alert channels, client reports, temporary access and Cloudflare controls.
See what Ultra addsEvery Ultra plan has every Ultra feature. Only the number of sites changes, and every license is yearly.
$0 No account, no payment
$79 per year · 1 site
$179 per year · 5 sites
$599 per year · 25 sites
$1,799 per year · 100 sites
Every Ultra feature, on one site.Every Ultra feature, on up to five sites.Every Ultra feature, on up to 25 sites.Every Ultra feature, on up to 100 sites.
14-day money-back guarantee
Full refund within 14 days on any Ultra plan. Each plan renews yearly at the same price until you cancel.
Short answers to the questions we get asked most about BetterShield.
Yes. The audit, every plain-language explanation, all 16 fixes and their undo, two-factor authentication, passkeys, login protection, the recovery link, the activity log, incident response, the file check and the MCP server are free. There is no account and no payment. BetterShield Ultra is a separate paid add-on for people who look after sites for others.
No. BetterShield does not include a firewall and does not scan for or remove malware. It audits your configuration, hardens it with fixes you can undo, secures logins, logs activity, groups suspicious changes into incidents, compares WordPress core and directory plugins with the official WordPress.org copies, and watches your theme and the files nobody publishes for changes.
Every fix shows you what it will change before you apply it, and you can switch it off at any time. Where switching off cannot reach everything, the fix says so first: people signed out by a key change stay signed out, and browsers that already saw the HSTS header keep insisting on HTTPS until it expires.
Open your latest recovery link and press its one button. BetterShield’s sign-in protections pause for one hour and your settings stay exactly as they are. Using a link issues the next one straight away, on the page and by email, and printed recovery codes are a second way back in.
Only if you let it. The MCP connection is off until you turn it on under Agents › Connect, and reading and changing are separate switches. With only reading on, an assistant can look and change nothing. With changing on, it can apply and undo fixes and put a changed file back, and every change is recorded in the activity log. A change to how people sign in, or taking a protection off, waits for you to agree. Creating accounts or credentials, changing your recovery options, two-factor or alert settings, lifting lockouts and deleting log rows are never possible through a connection.
Not yet. The check against published vulnerability advisories is built, but no data source is connected in this version, and the Findings screen says so rather than showing an empty list as a clean result. Today BetterShield flags plugins the WordPress.org directory has closed or that have had no update for years, and its file check shows any core or directory plugin file that no longer matches the official copy.
No. There is no account and no sign-up: install the plugin from WordPress.org and it works.
Out of the box, BetterShield contacts WordPress.org only, to check your files and plugins, and those requests carry version numbers and plugin slugs, never your site address, email or username. Everything else is off until you turn it on: usage sharing (asked once in Quick Setup, where Skip sends nothing), the breached-password check, your own AI provider, and BetterShield Hub.
Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.
Requires WordPress 6.7 or newer and PHP 8.0 or newer.