BetterShield

Install BetterShield and run Quick Setup

5 min read

Install BetterShield, see what activation does, and work through each Quick Setup step with its choices and defaults.

BetterShield installs from WordPress.org. Activating it runs a first audit and opens Quick Setup, a short wizard listed under BetterShield › Quick Setup until you finish it.

Requirements

  • WordPress 6.7 or newer.
  • PHP 8.0 or newer. On older PHP it does not run, and shows a notice instead.

Install the plugin

  1. In your dashboard, go to Plugins › Add Plugin.
  2. Search for “BetterShield”, then install and activate it.

To install by hand, upload the bettershield folder to /wp-content/plugins/ and activate it on the Plugins screen.

What activation does

  • A read-only audit runs, so the Overview has a score straight away.
  • A single-use recovery link is emailed to the site’s admin address. It gets you back in if you are locked out.
  • Quick Setup opens the first time you press Activate on the Plugins screen. Otherwise (bulk, WP-CLI or another plugin’s installer), the Overview shows a Run the Quick Setup card.
  • No hardening fix is switched on. Login attempt limits, a hidden bot check, public form limits, minimum password lengths and email alerts do start now, and each can be switched off.

Note: On multisite, each site gets its own Quick Setup the first time its administrator opens BetterShield.

Quick Setup, step by step

Up to seven steps; two appear only when they apply. Each step before Ready has Skip, and a skipped step changes nothing.

1. Getting started

Welcome to BetterShield asks one question, under Usage Data.

  • Get Started turns usage sharing on: at most once a day, your site address and title, admin email, software versions, language, plugins and theme go to WPDeveloper. Nothing about visitors, users or security events. What we collect? lists every field.
  • Skip sends nothing. You are reminded once, a week later.

Sharing stays off until you press Get Started, and can be turned off under Settings › General. On multisite, only a super admin is asked.

2. Coexistence (only with another security plugin)

Another security plugin is active shows one row per job both plugins would do.

OptionWhat it doesWhy it mattersDefault
Login attempt limitsKeep [other plugin] (BetterShield’s limit goes off) or Use BetterShield.Two limits lock a person out twice.Keep the other plugin
Two-factorKeep [other plugin] or Use BetterShield.Nobody is asked for two codes.Keep the other plugin
Activity logKeep both or Use BetterShield only.Two logs do no harm.Keep both
File change monitoringKeep both or Use BetterShield only.Two watchers do no harm.Keep both

Press Save choices; nothing changes before that. BetterShield never switches the other plugin off; deactivate it yourself when ready.

3. Your site

OptionWhat it doesWhy it mattersDefault
Who signs in to this site?Just me or Me and a team.A team is offered required two-factor for administrators next.Just me, unless administrators already need two-factor
Is this site behind Cloudflare or another proxy?No, direct, Yes, Cloudflare or Yes, another proxy.Behind a proxy, one lockout could block every visitor. Add another proxy’s addresses in Protect › Login & Access.No, direct, or Yes, Cloudflare when detected
Security alertsAdd another email adds recipients, up to 5 in total.Urgent alerts reach somebody.Admin address
Weekly summary, every MondayOne email: what changed, was found and was done.Arrives on quiet weeks too.On
Instant alerts for high and criticalSent as it happens.Some things cannot wait a week.On

Press Save and continue.

4. Way back in

Titled Your way back in.

  1. Under Recovery, tick I received the recovery email, or press Resend (a new email stops the old link working).
  2. Or press Download offline recovery codes. They work without email; keep them off this site.
  3. Optional: Set up two-factor for your account. Scan the QR code, press Verify code, then save your ten backup codes and confirm. Later leaves it for Protect › Two-Factor.

With Me and a team, Require two-factor for Administrators unlocks once you tick the email or download the codes. Administrators get 14 days by default; after that the dashboard waits until they set it up, but signing in always works.

5. Safe fixes

Five fixes that cannot lock anyone out: Turn off the file editor, Hide the WordPress version, Block directory browsing, Stop username discovery and Add security headers.

  • Each is ticked unless it is Already on, and previews its effect. One that warns of a conflict, or that your server cannot support, starts unticked.
  • Stop username discovery also gives a wrong password and an unknown username the same answer.
  • Press Apply 3 fixes (the button counts what you ticked), or Continue with none ticked.

Changes that could lock people out or are slow to undo, like the login URL or HSTS, stay off until you choose them in Protect › Hardening.

Only for people who can install and activate plugins. Switches start off; Continue installs only the WPDeveloper plugins you switch on.

7. Ready

You’re set up shows your Security grade, usage sharing, recovery, two-factor, the safe fixes (with Undo beside each one BetterShield applied) and where alerts go. Connect to BetterShield Hub is optional. Then press Go to BetterShield Dashboard.

Leave, skip or run it again

  • Leave partway: your answers are kept. The Overview card Finish the Quick Setup has Continue the setup, which opens where you stopped.
  • Skip to the end: skipping the step before Ready finishes the setup.
  • Run it again: a finished setup leaves the menu. Go to Settings › General and press Run Quick Setup again. It opens with your current settings and changes only what you change.

Where to go next

Read your score on Overview, then work through Findings and Protect › Hardening.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield