BetterShield
Free WordPress security plugin

Find and fix WordPress security issues.

BetterShield runs 54 security checks on your site, shows you exactly what is at risk in plain language, and fixes what it can in one click, with your approval. Each fix shows what it will change first, and you can switch it off again.

Security audit Example: review, approve, undoExample

Example audit: security score 86 out of 100. Two findings fixed, one waiting for review.

  • The dashboard file editor is enabled Fixed Open
  • User profiles are publicly listable Fixed Open
  • XML-RPC is enabled Fixed Open

Six jobs, one plugin

BetterShield inside your dashboard, screen by screen.

Security score

58 Grade D

54 checks · 9 open findings

  • A WordPress core update is available High
  • The dashboard file editor is enabled Medium
  • XML-RPC is enabled Medium
  • Common security response headers are missing Low
1 of 6 · Audit

A score that shows its workings

54 read-only checks across access, exposure, updates, server and configuration. Each finding says what it is, why it matters and what acting on it could break.

Score and findings guide

Hardening

16 fixes · each previewed before it applies

  • Stop PHP running in uploads On
  • Stop publishing the WordPress version On
  • Send security response headers On
  • Disable the dashboard file editor Turned on just now

Dashboard file editor disabled. Undo

2 of 6 · Hardening

Fix it in one click

16 fixes, each previewed before anything changes. Switching one off removes what it wrote, and the two that cannot reach everything, new sign-in keys and a long HSTS setting, say so first.

Hardening guide
  • Pause after failed sign-ins 5 in 15 min → 15 min
  • Require two-factor for Administrator · Editor
  • Passkeys Fingerprint · face · device PIN
3 of 6 · Sign-in

Guessing stops at the door

By default, 5 failed sign-ins in 15 minutes pause that connection for 15 minutes. Two-factor works with any authenticator app, passkeys sign people in with a fingerprint, face or device PIN, and you can require two-factor by role.

Login and access guide

Recovery

Checked every day, ready when you need it

  • Recovery link Ready
  • Pauses sign-in protections for 1 hour

Printed recovery codes · 2 used

4 of 6 · Recovery

Locked out? Get back in.

A single-use recovery link by email, or a printed recovery code, pauses the sign-in protections for one hour while you put things right. No FTP, no call to your host.

Locked-out guide

Site activity

Today · 4 events

  • Sarah signed in with a passkey 09:41
  • WooCommerce updated to 9.3.1 09:44
  • Role changed: editor to author 10:02
  • Yesterday sealed 00:00
5 of 6 · Activity

Who changed what

Sign-ins, accounts, roles, plugins, themes and core, with who and when, searchable and kept 30 days. Each finished day is sealed, so an edit or deletion shows up as a finding.

Activity log guide

Requests

Changes an assistant has worked out, waiting for you

Change the sign-in address

Proposed by Claude · changes how people sign in

  • Read the security score 09:12
  • Applied: Disable XML-RPC · undo kept 09:14
6 of 6 · AI assistants

Your AI asks, you decide

Claude, ChatGPT or another assistant reads your site’s security over MCP. Fixes that switch off cleanly can apply straight away; anything heavier arrives as a plan you agree to.

Connect an AI assistant

Security isn’t more alerts. It’s fewer open doors.

Most security plugins tell you whether your site is protected. BetterShield tells you what it checked and what it found, and fixes what it can, with your approval.

Illustration: three alerts from a typical security plugin give way to three open doors BetterShield finds (nothing limiting sign-in attempts, XML-RPC switched on, and the dashboard file editor switched on), and then to the same three closed.

Already inside the free plugin

The audit, the fixes and everything around them. No account, no payment.

Security audit and score

54 read-only checks, a score that shows its workings, and a plain-language explanation of every finding. Not ready for one yet? Snooze it for 7 or 30 days.

One-click hardening

16 fixes, each showing what it will change first. Every one has an undo that never expires.

Login protection

Repeated failed sign-ins pause that connection, with an allowlist, a blocklist and a hidden bot check on the forms.

Two-factor and passkeys

Any authenticator app with 10 single-use backup codes, and passkeys with a fingerprint, face or device PIN. Require them by role.

Lockout recovery

A single-use recovery link and printed recovery codes get you back in without FTP or a call to your host.

Activity log

Sign-ins, accounts, roles, plugins, themes and core, with who and when. Each finished day is sealed, so a later edit or deletion opens a finding.

File integrity

WordPress core and directory plugins compared with the copies WordPress.org publishes, showing exactly which lines changed. One click puts the official file back, and the replaced file is kept, never deleted.

Vulnerability alerts, soon

The check against published vulnerability advisories is built, but no data source is connected in this version. The Findings screen says so, rather than showing an empty list as a clean result.

Incidents

Related access and file changes are joined into one incident, with signs of an account takeover flagged. You review the response plan before anything changes.

Example site · 30 days

Security is a direction, not a snapshot

BetterShield keeps each day’s score, so the Overview can show which checks opened, passed or changed severity since an earlier day, with the score then and now.

Example site: the score rose from 54 to 88 in 30 days. The first fixes were applied on day 5, it dipped on day 16 while a plugin update was waiting, and it was back up on day 18.
AI assistants

Ask your AI. You decide what it changes.

Turn on the built-in MCP server and Claude, ChatGPT, Cursor, Codex or another assistant can read your site’s security through 18 bounded, read-only abilities.

Changing is a second switch, off by default. With it on, an assistant can apply and undo fixes, and every change is recorded in the activity log. A change to how people sign in, or taking a protection off, waits for you to agree.

Never possible through a connection: creating accounts or credentials, changing recovery, two-factor or alert settings, lifting lockouts, or deleting log rows.

ClaudeChatGPTCursorCodex yoursite.com · changes allowed

What should I fix first?

Used Read the audit → score 58 · 9 open findings

Start with the dashboard file editor. Turning it off is a one-click fix with an undo, so I can do that now. Changing the sign-in address needs your agreement first.

Used Apply a fix → Disable the dashboard file editor · undo kept

Change the sign-in address: waiting in Agents › Requests
Illustration. Claude, ChatGPT, Cursor and Codex are trademarks of their owners.
BetterShield Ultra

Keeps working when you log off

A paid add-on for people who look after sites for others: two-factor setup at sign-in, trusted devices, alert channels, client reports, temporary access and Cloudflare controls.

See what Ultra adds
Overnight on 12 sites Example · 4 events
  1. 01:12 wp-config.php changed on shop.example caught by the hourly watch
  2. 02:47 Temporary access ended on acme.example previous roles put back
  3. 03:05 Sign-in lockout on blog.example network challenged at Cloudflare
  4. 07:00 Client report for Acme Dental 3 recipients · sent

The essentials are free. Ultra when you look after more.

Every Ultra plan has every Ultra feature. Only the number of sites changes, and every license is yearly.

Free

From WordPress.org

$0 No account, no payment

  • 54-check audit and score
  • 16 one-click fixes, each with an undo
  • Login protection, two-factor and passkeys
  • Activity log and file integrity check
  • Lockout recovery without FTP
  • Incidents that group related events
  • MCP server for AI assistants
Get BetterShield free

Ultra PersonalBusinessAgencyAgency Plus

Everything in Free, plus
How many sites?

$79 per year · 1 site

$179 per year · 5 sites

$1,799 per year · 100 sites

Every Ultra feature, on one site.Every Ultra feature, on up to five sites.Every Ultra feature, on up to 25 sites.Every Ultra feature, on up to 100 sites.

  • Two-factor setup at sign-in, passkey policy and trusted devices
  • Slack, webhook and syslog alert channels
  • Scheduled client reports
  • Temporary access that ends on its own
  • Cloudflare controls (WordPress 7.0 or newer)
  • 90 days of activity history

14-day money-back guarantee

Full refund within 14 days on any Ultra plan. Each plan renews yearly at the same price until you cancel.

FAQ

Frequently asked questions

Short answers to the questions we get asked most about BetterShield.

Is BetterShield free?

Yes. The audit, every plain-language explanation, all 16 fixes and their undo, two-factor authentication, passkeys, login protection, the recovery link, the activity log, incident response, the file check and the MCP server are free. There is no account and no payment. BetterShield Ultra is a separate paid add-on for people who look after sites for others.

Does it include a firewall or a malware scanner?

No. BetterShield does not include a firewall and does not scan for or remove malware. It audits your configuration, hardens it with fixes you can undo, secures logins, logs activity, groups suspicious changes into incidents, compares WordPress core and directory plugins with the official WordPress.org copies, and watches your theme and the files nobody publishes for changes.

Will the fixes break my site?

Every fix shows you what it will change before you apply it, and you can switch it off at any time. Where switching off cannot reach everything, the fix says so first: people signed out by a key change stay signed out, and browsers that already saw the HSTS header keep insisting on HTTPS until it expires.

What happens if I lock myself out?

Open your latest recovery link and press its one button. BetterShield’s sign-in protections pause for one hour and your settings stay exactly as they are. Using a link issues the next one straight away, on the page and by email, and printed recovery codes are a second way back in.

Can an AI assistant change my site?

Only if you let it. The MCP connection is off until you turn it on under Agents › Connect, and reading and changing are separate switches. With only reading on, an assistant can look and change nothing. With changing on, it can apply and undo fixes and put a changed file back, and every change is recorded in the activity log. A change to how people sign in, or taking a protection off, waits for you to agree. Creating accounts or credentials, changing your recovery options, two-factor or alert settings, lifting lockouts and deleting log rows are never possible through a connection.

Does BetterShield detect vulnerable plugins?

Not yet. The check against published vulnerability advisories is built, but no data source is connected in this version, and the Findings screen says so rather than showing an empty list as a clean result. Today BetterShield flags plugins the WordPress.org directory has closed or that have had no update for years, and its file check shows any core or directory plugin file that no longer matches the official copy.

Do I need an account?

No. There is no account and no sign-up: install the plugin from WordPress.org and it works.

Does BetterShield send my data anywhere?

Out of the box, BetterShield contacts WordPress.org only, to check your files and plugins, and those requests carry version numbers and plugin slugs, never your site address, email or username. Everything else is off until you turn it on: usage sharing (asked once in Quick Setup, where Skip sends nothing), the breached-password check, your own AI provider, and BetterShield Hub.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield