BetterShield
Security auditHardeningAI assistants

Introducing BetterShield: a free WordPress security plugin

BetterShield team · · 9 min read

A list of security warnings tells you something needs attention, then leaves the work with you: what each one means, what to change, and what that change might break. BetterShield is a free WordPress security plugin that takes the next step. It finds what is open on your site, explains it in plain language, and, where a one-click fix exists, closes it once you approve.

It is on WordPress.org now, at version 1.1.0, with no account and no sign-up.

Quick summary

  • 54 read-only checks give your site a score out of 100 and a grade from A to F.
  • 16 one-click hardening fixes, all off until you choose them, each with a preview first.
  • A way back in if you are locked out: a recovery link, printed codes and safe mode.
  • Two-factor, passkeys, login protection, an activity log and file checks are included.
  • Nothing leaves your site out of the box apart from WordPress.org file and plugin checks.

The idea: close what is open

BetterShield starts from one question: what on this site is open that does not need to be? An administrator account nobody has used in six months. The dashboard file editor left on. Installer tools left behind after a migration.

For each finding, it tells you what it is, why it matters and what could break if you act on it. Where a one-click fix exists, it shows exactly what the fix will change, and nothing changes until you choose it. A check that could not run is never counted as a pass.

How this free WordPress security plugin works, in three steps

1. Run the audit and read your score

Activation runs a read-only audit straight away: 54 checks across Access (14), Exposure (14), Updates & extensions (11), Server (8) and Configuration (7). Nothing on the site is changed to produce the result.

The score starts at 100. Each open finding takes points off by severity: 25 for Critical, 12 for High, 7 for Medium, 3 for Low and none for Info. A score of 90 or more is an A, 75 a B, 60 a C and 45 a D; below 45 is an F.

On BetterShield › Overview, Worth doing first lists up to three open findings with a one-click fix, most serious first. Explain shows why one matters and what could break. On Findings, Remind me later snoozes a finding for 7 or 30 days, and Not applicable sets aside one that will never apply. All 54 are on the checklist, and the Score and findings guide covers both screens.

2. Preview a fix, then apply it

BetterShield handles WordPress hardening with 16 one-click fixes. Ten are on Protect › Hardening, and the six that affect signing in are on Protect › Login & Access. All start off.

Press Preview the change to see what a fix would do; the preview changes nothing. Then turn the switch on. To take the fix off, turn the switch off, and any files it wrote are put back as they were.

Two fixes say up front what taking them off cannot reach. Strengthen and rotate the sign-in keys signs other people out, and those sessions stay ended. Tell browsers to refuse plain HTTP (HSTS) stays in browsers that saw a long setting until it expires, so start with five minutes. See the Hardening guide.

3. Keep a way back in

At activation, BetterShield emails a single-use recovery link to the site’s admin address. Open it and press Pause protection and continue: safe mode pauses BetterShield’s protections for one hour, your settings stay as they are, and the next link is issued straight away.

A link lasts 90 days. On Protect › Recovery you can replace it, and Issue recovery codes gives you eight printed, single-use codes that work without email. Before any change to how people sign in, BetterShield checks that one of these works. See the Locked out guide.

Sign-in protection, two-factor and passkeys

A few protections start at activation, and each can be switched off: login attempt limits (by default, 5 failed sign-ins in 15 minutes pause that connection for 15 minutes), a hidden bot check on the login, registration, WooCommerce account and comment forms, and limits on public forms.

Two-factor works with any authenticator app, with 10 single-use backup codes, and is never enforced until the app is proven to work. You can require it by role, with a 14-day grace period by default. Passkeys sign people in with a fingerprint, face or device PIN, and only the public half of the key is stored. See the Login & Access and Two-factor and passkeys guides.

Activity log, file checks and incidents

  • Activity log: sign-ins, account and role changes, password resets, and plugin, theme and core changes, with who and when. Filter, search and Export CSV, with 30 days of history. Each finished day is sealed, so an edit or deletion opens a high-severity finding.
  • File changes: WordPress core and directory plugins are compared with the official copies WordPress.org publishes. Put the official file back restores a changed file, and yours is kept in quarantine, never deleted. Your theme, wp-config.php and .htaccess are watched for changes.
  • Incidents: related access and file changes are grouped into one incident. Prepare response plan lists actions; nothing changes until you press Apply selected actions, and BetterShield checks again afterward.

AI assistants, with you in charge

BetterShield has a built-in MCP server, so an assistant such as Claude, ChatGPT, Cursor or Codex can read your site’s security. On Agents › Connect, Three steps to a connected assistant has a switch for each step, all off by default:

  1. Let my agent read security information offers 18 read-only abilities, from your score and findings to the activity log and file check.
  2. Let agents act: changes that can be undone right away, anything heavier once you agree is optional.
  3. Let an assistant connect to this site opens the connection.

With changes allowed, seven fixes that reverse right away apply directly. Heavier changes, such as the sign-in fixes or putting a changed file back, arrive as a plan a person agrees to. Creating accounts or credentials, changing recovery options, weakening two-factor or alerts, lifting lockouts and deleting log rows never happen through a connection. Limits: 5 changes of one kind and 30 plans per hour. See Connect an AI assistant.

BetterShield Hub for many sites

BetterShield Hub is a free, optional dashboard for people who look after several sites. Connect each site from BetterShield › Hub, choose Read this site only or Read this site and apply fixes that can be undone, and approve it on the site’s own consent page. A change to how people sign in, or taking a protection off, waits for a person to agree each time. The site never contacts the hub, and Disconnect ends it at once. Everything in the plugin works without it. See BetterShield Hub.

What leaves your site

Out of the box, BetterShield contacts WordPress.org only, to check your files and plugins. Those requests carry version numbers and plugin slugs, never your site address, email or username.

Everything else is off until you turn it on: usage data (asked once in Quick Setup, where Skip sends nothing), the breached-password check, your own AI provider and BetterShield Hub. What BetterShield contacts lists what each one sends.

What BetterShield does not do

It does not yet tell you whether an installed plugin version has a known vulnerability. The check against published advisories is built, but no data source is connected in 1.1.0, and the Findings screen says so rather than showing an empty list as clean. Today it flags plugins closed on WordPress.org or with no update for two years. It is also not a firewall, and it does not scan for or remove malware.

BetterShield Ultra

BetterShield Ultra is a separate, paid add-on for people who look after sites for others. It needs the free plugin on the same site and adds things like two-factor setup at sign-in for chosen roles, trusted devices, Slack and webhook alerts, a scheduled client report, temporary access and 90 days of activity history. Everything above is in the free plugin. See Ultra.

How to get started

  1. Go to Plugins › Add Plugin, search for “BetterShield”, then install and activate it, or get it from WordPress.org. It needs WordPress 6.7 and PHP 8.0 or newer.
  2. Activation runs the first audit, emails your recovery link and opens Quick Setup.
  3. On Your way back in, tick I received the recovery email or press Download offline recovery codes.
  4. Review the five safe fixes, which cannot lock anyone out, and apply the ones you want.
  5. Press Go to BetterShield Dashboard and start with Worth doing first.

The Install and set up guide walks through every step.

Common mistakes

  • Changing sign-in before saving a way back in. Keep the recovery email or printed codes somewhere off the site first.
  • Starting HSTS at six months. Use five minutes first. A long setting stays in browsers after you turn the fix off.
  • Two plugins doing the same job. Use Quick Setup to choose which plugin keeps login limits and two-factor.
  • Deleting the plugin to remove fixes. By default, applied fixes, including .htaccess rules, stay after you delete it. Turn off the ones you do not want first.

Frequently asked questions

Is BetterShield really free?

Yes. The audit, all 16 fixes, two-factor, passkeys, login protection, the recovery link, the activity log, incident response, the file check and the MCP server are free. There is no account and no payment.

Will the fixes break my site?

Each fix previews what it will change and stays off until you turn it on. Turning it off removes what it changed. Where that cannot reach everything, such as sessions ended by a key change, the fix tells you first.

What happens if I lock myself out?

Open your latest recovery link and press Pause protection and continue. BetterShield’s protections pause for one hour and your settings stay as they are. Printed codes work without email, and wp bettershield recover does the same from WP-CLI.

Conclusion

BetterShield is built for the moment after an audit: you know what is open, you see what a fix will change, and you decide. No hardening fix is switched on until you choose it, and there is always a way back in.

The features page has the full list, and support is there if you get stuck.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield