BetterShield
Changelog

What’s new in BetterShield

Every release of BetterShield and BetterShield Ultra, newest first, in the words of each release’s own notes. Switch between them below.

The free plugin’s notes are also on its WordPress.org page. Ultra’s Automatic Response entries are left off until vulnerability data is connected.

  1. Free

    BetterShield 1.1.0

    This update adds a built-in MCP server for AI assistants, the optional BetterShield Hub, protection for the comment, password reset and sign-up forms, more audit checks, snoozable findings and a sixteenth one-click fix. Recommended for all sites.

    56 changes 31 added · 20 improved · 5 fixed

    Added 31

    • Usage Data Optional usage data sharing, asked once in Quick Setup and switchable under Settings > General
    • Overview See which checks opened, passed, changed severity or were marked not applicable since an earlier day, with the score then and now
    • Security Audit Four new checks: unfiltered code below administrator, script uploads below administrator, this plugin's automatic updates switched off, and world-writable folders under wp-content
    • Recovery Checks that a recovery link or printed code works before any change to how people sign in, from the dashboard or wp bettershield harden (--force to go ahead)
    • Incidents An email change, a password change and a new application password on one privileged account within an hour are recorded together as one high signal
    • Incident Response Re-checks the site after a response runs and lists what is still open
    • Overview Notes when failed sign-ins or the scheduler's timing are far outside this site's last 30 days
    • AI Explanations Explain my audit summarizes the open findings in three short paragraphs that cite each finding
    • Settings Import Bring over protections and sign-in attempt limits from another security plugin, with a preview and an undo
    • MCP Server Connect Claude, ChatGPT or any MCP assistant to read the audit, activity and file check, apply fixes you can undo and restore changed files, with every call logged
    • Agents A new Agents section with Connect, Requests, Permissions and Surface tabs
    • BetterShield Hub Optional hub connection from BetterShield > Hub, Settings or the end of Quick Setup, approved once on the site's own consent page
    • Overview A storage card that names a missing database table or column and offers a Repair
    • Uninstall A third choice when deleting the plugin: pack the quarantined copies into one archive, then remove them
    • Hardening A sixteenth fix: refuse new passwords found in known breaches, off by default
    • File Integrity Reports a new .user.ini file that appears after the site's configuration was recorded
    • Security Audit Names PHP files and folders in the plugins folder that no installed plugin claims
    • Security Audit Flags directory plugins with no update for two years, with the last-updated date
    • Form Protection Comment bursts are held for moderation, and repeated password resets and sign-ups from one connection are paused
    • WooCommerce Customers manage two-factor, passkeys and signed-in devices from a Sign-in security tab on My Account
    • Login Protection Block a username from signing in
    • Security Audit Finds installer and database tools left in the web root, with quarantine from the finding
    • Security Audit Checks whether admin-ajax shares signed-in answers with other websites, and names where the policy was widened
    • Security Audit Detects a sign-in page served by a page cache or CDN
    • Security Audit Checks the domain's SPF, DMARC and CAA records once a day
    • Security Audit Warns when free disk space runs low
    • Findings Snooze a finding for 7 or 30 days, with its own Snoozed filter and wp bettershield findings --status=snoozed
    • Plugins Screen Add New shows whether a plugin is closed on WordPress.org or has had no update for two years
    • Application Passwords Limit an application password to its REST routes, its network, or both, from Agents > Surface
    • Site Moves When the site address or folder changes, the Overview asks whether it is a staging copy or a move, with one undo
    • Incident Response Ask a privileged account for a new password, with an undo

    Improved 20

    • Quick Setup Previews what each fix will do before applying it, leaves risky fixes unticked, and undoes the applied set in one step
    • Request Protection Each public form has its own threshold, window and closing time, with a replay of the last two days before you save
    • Incidents Evidence names each row's network and links to the activity log for the incident's days
    • Activity Log Open everything from one person or one network from any log row, and narrow agent activity to one account
    • Multisite The network overview shows how many sites it lists and loads more on request on networks of more than 200 sites
    • Privacy Add-ons can declare a per-site personal data record so the privacy export finds it
    • Audit Says how many checks could be evaluated when a run could not check them all, and marks findings kept from an earlier run
    • File Integrity A changed file too long to compare whole shows the part that changed
    • File Integrity A plugin copy you reviewed and adopted stays quiet until it changes again
    • Login Protection Repeat lockouts within a day double in length, up to one day
    • Compatibility Recognizes one more security plugin, so the same job is not done twice
    • Settings Import Brings over sign-in attempt limits, allowed addresses, the breached-password check, username discovery block, version hiding and uploads protection from one more security plugin
    • Settings Export Blocked usernames are included in an exported settings file
    • File Integrity The Files screen groups changes by plugin and version, with Check again and Mark all expected (wp bettershield integrity recheck and expect)
    • Activity Log Notes which code files an update to a plugin outside the directory added or changed
    • Alerts Connecting an assistant, rotating its credential or approving an app sends an instant alert
    • Hardening The usage preview on the XML-RPC and application password fixes looks back across the whole activity record
    • Admin Menu The sidebar shows the BetterShield icon
    • Confirmations Applying an incident response, disabling the decoy URL and withdrawing an agent's confirmation ask once more before acting
    • Agents A credential connected while agents may not change the site is issued read-only

    Fixed 5

    • Login Protection Sign-in lockouts keep working right after an update, before the database is upgraded
    • Login Protection Lockouts stand down behind a proxy that forwards no visitor address, instead of locking all visitors out together
    • Multisite On installs with more than one network, the network dashboard and activity log show only that network's sites
    • Hardening A protection set to applied while safe mode is on is shown as paused
    • WP-CLI The agent-activity export carries every matching row, or says where it stopped
  2. Ultra

    BetterShield Ultra 1.0.1

    28 changes 4 added · 13 improved · 11 fixed

    Added 4

    • Network Edge Raise Cloudflare's security level, challenge the network of a sign-in lockout and deploy the managed ruleset from the Cloudflare tab, each change with an undo
    • Alert Channels Syslog collectors over UDP, TCP or TLS, with TLS required for a collector on the public internet
    • Alert Channels A destination can receive the whole activity record for the event classes you choose, not only the alerts
    • Overview A new Overview tab with one card per feature, showing whether each one is on

    Improved 13

    • Screens Ultra's tabs now open inside the BetterShield screen, in their own sidebar group that opens and closes
    • Screens Every card opens with its state, and each tab says what it is for and how much of it is on
    • Confirmations Raise the level, Deploy it, Run it now and Send one now ask once more before they act
    • Accessibility Screen readers hear "Saved.", and busy buttons keep keyboard focus
    • Privacy IP addresses are masked wherever the add-on shows or keeps them, including temporary access and trusted devices
    • Performance Visitors no longer load the licensing package, and signed-out page views skip the temporary access check
    • Policies A weakened two-factor or passkey policy is graded, named and can be undone
    • Policies The passkey card says it only reminds people, and links each account to where it can enroll
    • Temporary Access Times show on the site's clock with the time zone named, and a typed end time is kept to the minute
    • Client Report Send one now and Read it wait until the report's addresses are saved
    • Incident Response Shows Paused, with the reason, while a run would do nothing
    • License View details describes this add-on and every service it contacts
    • Notices The add-on's notices are marked as BetterShield's own

    Fixed 11

    • Temporary Access A grant ends at the time its email names, a grant whose account was deleted is removed, and a network delete removes it from every site
    • Alert Channels IPv6 and reserved IPv4 destinations are checked on every supported WordPress version, and an address nothing answers for says it could not be found
    • Network Edge One edge change at a time, and lockout blocks stay in place when the lockout list cannot be read
    • Network Edge Lockout blocks stand down while the site enforces no sign-in pauses
    • Two-Factor Policy A role added back to the policy gets its grace period again
    • Trusted Devices The device limit removes this site's oldest device, not the network's
    • Client Report Activity is filed under the area it happened in, and invalid recipients are refused instead of erasing the saved ones
    • Multisite Deleting a subsite removes the add-on's data for it, and a network deactivation clears the schedule on every site
    • Uninstall Deleting the add-on works with BetterShield inactive, releases the license and removes the per-role policy timer
    • Updates An update of the add-on, automatic or not, refreshes the list of settings it loads on every request
    • Startup The add-on stands down on PHP below 8.0 instead of breaking the site, and one uploaded before BetterShield activates and offers to install it
  3. Free

    BetterShield 1.0.0

    First public release

    10 changes 10 added

    Added 10

    • Security Audit 40 read-only checks, a score that shows its workings and a plain-language explanation of every finding
    • Hardening 15 one-click fixes, each showing what it will change first, each with an undo that never expires
    • Two-Factor Authentication Any authenticator app, 10 single-use backup codes, and passkeys
    • Login Protection Lockouts after repeated wrong passwords, an allowlist and a blocklist, session limits and an optional idle timeout
    • Recovery A recovery link, safe mode and printed offline codes, with daily readiness checks and optional weekly email tests
    • Activity Log Sign-ins, accounts, roles, plugins, themes and the plugin's own actions, with filters, search, CSV export and a daily seal
    • File Integrity Core and directory-plugin files compared with the copies WordPress.org publishes, with the difference shown and one click to restore a file
    • Alerts A weekly email summary that arrives on quiet weeks too, and high and critical events sent on their own
    • Tools WP-CLI commands, settings export and import, findings in Site Health, a dashboard widget, and a report of what connected agents can do
    • Multisite Every site's score in one table and rules a network can set once
  4. Ultra

    BetterShield Ultra 1.0.0

    First paid release

    6 changes 6 added

    Added 6

    • Login Security Two-factor by role with a grace period and an enrollment screen, trusted devices, passkey policy, prevented self-removal for enforced roles, the sign-in report and branded sign-in screens
    • Alert Channels Slack and JSON webhooks as a second route for BetterShield's alerts, alongside email
    • Client Report A scheduled report for the people who pay for the site and never sign in to it
    • Temporary Access A role grant that ends on the deadline you pick
    • Hourly Watch The check of unpublished code runs every hour instead of once a day
    • AI Explanations No hourly limit on plain-language explanations of a finding

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield