BetterShield

Get back in when you’re locked out

5 min read

Locked out of WordPress by BetterShield? Use your recovery link or a printed code to pause its protections for an hour and sign in again.

If BetterShield is stopping you from signing in, your recovery link or a printed recovery code pauses its protections for one hour, with nothing deactivated and no setting changed. You manage both under BetterShield › Protect › Recovery.

The recovery link is a private address for your site. BetterShield emailed it to the site’s administration email address when you activated it (and again if you resent it from Quick Setup), with the subject “[your site] Your BetterShield recovery link”. If a link has been used since, the newest one arrived in an email titled “Your BetterShield recovery link was used on [your site]”. A link you generated on the Recovery screen was shown there, not emailed.

  1. Open the newest link in your browser. Opening it changes nothing yet.
  2. On Pause protection and get back in?, press Pause protection and continue.
  3. The Safe mode is on page says when the pause ends. Under Save your next recovery link it shows a new link: copy it somewhere safe now. A copy is also emailed to the administration address.
  4. Press Go to sign-in and sign in with your username and password.

Each link works once: using it spends it and issues the next one straight away. A link also stops working 90 days after it was issued, or as soon as a newer one is generated. A spent, replaced or expired link shows “This recovery link or code is not valid.”

For that hour, BetterShield stops enforcing lockouts, the blocklist, a moved sign-in address, session limits and its two-factor step, so the standard sign-in page works again. Safe mode ends on its own; to end it sooner, press End safe mode now on the Overview.

Use a printed recovery code

Printed codes work without email. Each sheet lists eight codes and the address to use them at.

  1. Open the address printed on the sheet with one code added to the end, typed as printed.
  2. Press Pause protection and continue. Only that code is spent; your other codes keep working.
  3. The Safe mode is on page says how many codes you have left. Press Go to sign-in.

A code does not issue a new link. When your codes run low, issue a new set from the Recovery screen.

If you have neither

  • Locked out after wrong passwords. A sign-in lockout ends on its own (15 minutes by default, longer if it keeps happening within a day). The account’s email address also receives “[site name] Sign-in temporarily locked” with an unlock link: open it and press Clear the lockout.
  • Another administrator can still sign in. They can generate a new recovery link for you under Protect › Recovery, or fix whatever is blocking you.
  • You or your host can run WP-CLI. wp bettershield recover turns safe mode on for one hour and needs no user account. Add --hours=4 for longer (1 to 24 hours) or --new-link to print a fresh recovery link (the old one stops working). wp bettershield recover --end ends safe mode early.

Lost your two-factor device

  • Use a backup code. Setting up two-factor gave you ten backup codes. On the code screen, type one in place of the app code. Each works once.
  • No backup codes left? An administrator can open your account under Users, find Two-factor sign-in and press Turn off two-factor for this account. You then sign in with your password and set two-factor up again.
  • The only administrator? Your recovery link or a printed code gets you into the dashboard, because the two-factor step is not asked while safe mode lasts.

Before you need it

On BetterShield › Protect › Recovery, in the order the screen shows them:

OptionWhat it doesWhy it mattersDefault
Generate a new link (Generate recovery link if none exists)Makes a new recovery link, good for 90 days, and shows it once, with Copy link. The old link stops working. A link made here is not emailed.Keep it outside the site, such as in a password manager. In a link’s last 14 days, Findings shows “The recovery link is close to expiring”.One link, emailed at activation
Issue recovery codesShows eight single-use codes once, with Print and Copy all. Issue a new set replaces any unused codes.Your way back on the day email is broken.None until you issue them
Check readiness nowChecks the link, your unused codes, an administrator email address and the email path. Never uses a link or code.Shows a broken way back early.Runs daily on its own
Send a weekly recovery email checkSends a test email to your alert recipients at most once a week.Shows whether mail actually leaves the site.Off
Lock the site downSigns out every other dashboard session, refuses sign-ins from accounts that cannot manage the site, turns off XML-RPC and application passwords, and stops registrations, installs and updates. Never expires; Lift the lockdown ends it. The front end and a WooCommerce checkout keep working.For an emergency. Your recovery link pauses it too.Off

Before a change to how people sign in, such as moving the sign-in address or requiring two-factor for a role, BetterShield checks that you have a working recovery link or an unused printed code.

Note: On multisite, the network’s BetterShield › Network screen has a Recovery link for the network, which pauses enforcement on every site for an hour.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield