Harden your site with one-click fixes
Preview, apply and undo BetterShield’s 16 hardening fixes, trial some on real requests with Monitor first, and see what each one changes.
Ten fixes are on BetterShield › Protect › Hardening, and the six sign-in fixes are under Signing in on Protect › Login & Access. Every fix starts off, and nothing changes until one is turned on.
Preview, apply and undo
- Fill in any field the fix has, then press Preview the change. It lists what applying would do, changes nothing, and for XML-RPC and application passwords shows recent use.
- Turn the switch on. The row shows On since and Undo never expires.
- To undo, turn the switch off. Files the fix wrote are put back as they were.
A note beside the switch warns when another plugin already does the job. A fix your server cannot run shows Not available here.
Applying a Signing in fix first checks your recovery link or printed codes; going ahead anyway is logged. Every apply and undo is logged too, and safe mode pauses every fix.
Monitor first
Monitor first watches real requests without blocking anything. It works for Disable XML-RPC and four Signing in fixes: Change the sign-in address, Refuse application passwords, Keep low-privilege accounts out of the dashboard and Hide the dashboard from visitors.
- Choose a New observation window (1 hour, 24 hours or 7 days) and press Start monitoring with the fields above.
- It counts requests observed and matched.
- When the window ends, press Enforce reviewed settings. It needs a working recovery link or printed codes; undo still works.
Keep low-privilege accounts out of the dashboard also offers Automatic undo for the first 24 hours after 1, 5 or 10 signed-in denials (default Keep undo manual).
Note: A match is not proof of breakage, and no matches is not proof of safety.
The 16 fixes
In screen order, by group. The Signing in group is on Login & Access.
| Fix | What it does | Why it matters | Watch for |
|---|---|---|---|
| What the site reveals | |||
| Block public user listing | Hides usernames from the REST API, author links, the sitemap, embeds and sign-in errors. | Guessed usernames cannot be confirmed. | A mistyped lost-password address is still told a link is coming. |
| Stop uploads directories listing their contents | Adds a blank index.php to uploads folders that lack one. | Folders cannot be browsed as file lists. | Any web server. On a network, apply per site. |
| Hide sensitive files from visitors | .htaccess rules answer 404 for logs, wp-config backups, readme.html, license.txt, .git and .env. | A stray wp-config backup can expose the database password. | Not on nginx or IIS. On a network, main site only. |
| Stop publishing the WordPress version | Removes the version from the generator tag and asset addresses. | Scanners use it to choose what to try first. | Plugin and theme versions stay. |
| What can run | |||
| Disable XML-RPC | Answers xmlrpc.php with 403. The REST API is untouched. | Closes a legacy API and its pingbacks. | Jetpack features that need it. |
| Disable the dashboard file editor | Removes the plugin and theme code editors. | No code editing from the dashboard. | No change if wp-config.php already disables it, or on a network. |
| Stop PHP running in uploads | An uploads .htaccess rule answers 404 for PHP files. | An uploaded file can never run as code. | Not on nginx or IIS. From a network’s main site, it covers every site. |
| What browsers are told | |||
| Tell browsers to refuse plain HTTP | Sends HSTS for Five minutes, to prove it works (preselected) or six months, to This domain only (preselected) or every subdomain. | Browsers stop using plain HTTP. | HTTPS addresses only. See below. |
| Find out what a content policy would break | Sends a report-only content policy and lists what it would block. | You see the cost before anything is blocked. | Start enforcing this policy unlocks after 7 days with no reports. |
| Send security response headers | Adds four standard headers: content type, framing, referrer and Topics API. | Stops content-type guessing and framing by other sites. | Headers your server already sends are left alone. |
| Signing in | |||
| Change the sign-in address | Moves sign-in to your New sign-in address. wp-login.php answers 404. | Quieter logs, not a stronger door. | Note it off the site. The recovery link restores the standard page. |
| Refuse application passwords | Refuses them for Accounts that can manage this site (preselected) or Every account. Nothing is deleted. | They sign in without the second factor. | Tools that use them stop working. |
| Refuse passwords found in known breaches | Checks new passwords set by signed-in people against Pwned Passwords, sending only five characters of a hash. | A strong-looking password can be on a breach list. | Never affects signing in. Registration and reset forms are not checked. |
| Keep low-privilege accounts out of the dashboard | Sends the chosen role (preselected: Subscriber) from wp-admin to the front page, except their profile. | Subscribers and customers have no need for wp-admin. | Never applies to a role that can manage the site. |
| Hide the dashboard from visitors | Signed-out visitors get a 404 at /wp-admin/ instead of the sign-in form. | A moved sign-in address is not given away. | admin-ajax.php keeps working. |
| Strengthen and rotate the sign-in keys | Mixes a strong secret into the session keys and adds Rotate keys now. | Forging a session also needs this secret. | Signs other accounts out. On a network, rotate from BetterShield › Network. |
What undo cannot reach
- Strengthen and rotate the sign-in keys: sessions it ended stay ended, and Rotate keys now has no undo.
- Tell browsers to refuse plain HTTP: a browser that saw the six-month or every-subdomain setting keeps insisting on HTTPS until it expires, whatever you undo. Start with five minutes.