BetterShield

Install BetterShield Ultra and activate your license

5 min read

Install the BetterShield Ultra add-on beside the free plugin, activate your license for updates, move it to another site, and see what it adds.

BetterShield Ultra is a separate, paid add-on. It adds to the free BetterShield plugin and does not replace it, so BetterShield stays active on the same site. Its license is on BetterShield › Ultra › License. For plans and prices, see BetterShield Ultra and Pricing.

Requirements

  • BetterShield, active on the same site.
  • WordPress 6.7 or newer, and PHP 8.0 or newer. On older PHP, Ultra stands down with a notice.
  • The Cloudflare tab also needs WordPress 7.0 or newer.

Install Ultra

  1. Install BetterShield from WordPress.org, if it is not on the site yet (see Install and set up).
  2. Go to Plugins › Add Plugin › Upload Plugin, upload bettershield-ultra.zip, then install and activate it.
  3. Open BetterShield. Its sidebar now reads BetterShield Ultra, with an Ultra part for the add-on’s screens.

Without BetterShield, Ultra starts nothing, and the Plugins screen offers Install and activate BetterShield (or Activate BetterShield) to anyone allowed to install and activate plugins. If BetterShield is too old, the notice asks you to update it.

Activate your license

Open BetterShield › Ultra › License. The License link beside Ultra on the Plugins screen opens the same tab. It needs an account that can manage BetterShield.

  1. Find your key in your wpdeveloper.com account. The tab’s first step links there.
  2. Paste it into License key and press Activate.
  3. If the store asks for a code, it emails one to the address on the purchase. Enter it in Confirmation code and press Confirm.

The card then shows Active, and the end date if there is one.

Note: After a failed exchange with the store, the tab holds off for an hour. Try now tries at once.

What the license does

Your license key is what brings Ultra its updates.

  • Ultra checks the store for new versions with your key, and updates arrive on the Plugins screen like any plugin’s.
  • A stored key’s status is checked weekly. If the store cannot be reached, the last known status stays.
  • Activating, releasing and a lapse the store reports are recorded in the activity log. The key never is.
  • Without an active license, one line on the Plugins screen says so, with Activate it or See why.

Move a license to another site

  1. On the old site, open BetterShield › Ultra › License, press Stop using this license here, then Yes, do it. The key is freed for another site.
  2. On the new site, enter the key and press Activate.

If the store cannot be reached, Forget it on this site anyway removes the key here only; release the activation from your account too. If Settings › General asks for your password before a protection is removed, releasing asks too. Deleting Ultra also releases the license, if the store answers, and removes the key.

Note: On multisite, each site has its own License tab and key.

When the license expires

The card shows Expired once the end date the store gave has passed. Renew it to receive updates again.

Other states the card can show: Disabled, Not recognized, Not active for this site, A different product, No activations left.

If you deactivate Ultra

The site goes back to BetterShield’s free features on the next request, and Ultra’s settings are kept for when you activate it again. Also:

  • Changes Ultra made to your Cloudflare zone are put back, where they can be.
  • The activity log shows 30 days again, and the daily cleanup removes older entries. Handled incidents are kept 30 days, not 180.
  • A temporary access grant keeps its added role until Ultra is active again to take it back. End grants first.

What Ultra adds

Most of it is off until you set it up. The longer history, the hourly check and the lifted limit on explanations start as soon as Ultra is active. The first screen, Ultra overview, has one card per feature saying whether it is on.

Sign-in

  • Policies: after a grace period, people in the roles you choose who have no second factor are taken to a setup screen right after their password. Also a passkey reminder by role, and stopping people in an enforced role from turning their own second factor off (an administrator always can). See Sign-in policies.
  • Trusted devices: a trusted browser skips the code screen for the days you set, up to 90. Off by default. See Trusted devices.
  • Temporary access: a role for one hour to 30 days, taken back on its own, never from the last administrator. End now ends it early. See Temporary access.
  • Sign-in screens: your logo, accent color and words on the code and setup screens. See Sign-in screens.

Reports and alerts

  • Sign-in report: who has two-factor or a passkey, by role, with Download as CSV. See Sign-in report.
  • Alert channels: alerts in Slack, at a webhook or in a syslog collector, as well as by email. Up to five. See Alert channels.
  • Client report: a weekly or monthly email for the people who pay for the site, to up to five recipients. See Client report.

Response

  • Automatic incident response: acts on a correlated incident with the action types you save, such as removing roles or ending sessions. See Automatic response.
  • Unpublished code, checked hourly: drop-ins, must-use plugins, the active theme, wp-config.php, the root .htaccess and plugins with no published file list, hourly instead of daily. Also on Automatic response.
  • Cloudflare: raise the zone’s security level, challenge the network of a sign-in lockout, and deploy Cloudflare’s managed ruleset. Needs a Cloudflare token in Settings › Connectors. See Cloudflare.

In BetterShield’s own screens

  • 90 days of activity log and 180 days of handled incidents, instead of 30. Entries already removed do not come back.
  • No hourly limit on plain-language explanations (20 an hour per account without Ultra).
  • Draft a summary for my client on an incident (with an AI provider connected), and an Incidents tab on a multisite network’s Activity screen.
  • Put this back and Suspend this account on recorded changes in the activity log.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield