BetterShield

Read your score and work through findings

6 min read

What your BetterShield score and grade mean, what the Overview shows, and how to fix, snooze or set aside each finding.

BetterShield runs 54 read-only checks and turns what they find into a score out of 100. BetterShield › Overview shows where the site stands and what to do first. BetterShield › Findings lists every finding in full.

How the score works

The score starts at 100. Each open finding takes off points by severity, down to a floor of 0.

SeverityPoints off while open
Critical25
High12
Medium7
Low3
Info0
GradeScore
A90 to 100
B75 to 89
C60 to 74
D45 to 59
FBelow 45
  • A snoozed finding still counts. A finding marked Not applicable does not.
  • The audit runs on activation, daily, and when you press Run audit in the bar at the top of each BetterShield screen. It only reads: nothing on the site is changed to produce the score.
  • A check that could not run is never counted as a pass.

All 54 checks are on the Security checklist.

The Overview screen

Notices above the score

Shown only when they apply: the Quick Setup card, a card when the site’s address changes, the safe mode banner (End safe mode now), a storage card (Repair), and notes when alerts are muted, no daily audit is scheduled, or the score is over 48 hours old.

The score band

  • The score, with its grade (such as Grade B).
  • What the fixes below are worth: the points the listed fixes would add, and the score they would reach.
  • Posture, last 30 days: a column of dots per recorded day, and whether the score held or moved. Appears once two days are recorded.
  • Three counts: checks run, could not be checked and open findings.

Worth doing first

Up to three open findings with a one-click fix, most serious first, each with its severity, points (such as -12 pts) and area.

  • Apply fix applies it at once. A Fixed: line with Undo stays until you leave the screen.
  • Explain opens why it matters, what could break, and Open this finding.
  • The heaviest open finding without a one-click fix is named above the list, with What to do about it.
  • The link with your count, such as All 12 open findings, opens the Findings screen.

The rest of the main column

A line under Worth doing first counts any snoozed findings it leaves out; they still count in the score. Then each card appears only when it has something to say:

CardWhat it shows
Explain my auditThe open findings in three short paragraphs, from your connected AI provider (WordPress 7.0 or newer).
What could not be checkedWhich checks could not answer this time, and when each last did.
Done recentlyThe latest hardening fixes applied, each with Undo while that undo can still work.
Since you last lookedWhat changed since your last visit, by whom and when.
What changed, check by checkPick a day under Compared with: checks Opened since, Severity changed, Passed since and Marked not applicable since, and the score then and now.

The column ends with four counts (audits run this week, hardening items active, events logged this week and last change made), what BetterShield adds to page views here (measured on one view in 20), and one closing line: Nothing needs urgent attention. or Some findings deserve a look., with when the next audit runs.

The side column

  • Your way back in: recovery link status and offline codes left, with Check the link and Print offline codes.
  • Who does which job: when another security plugin is active.
  • Protection: how many protections are switched on.
  • Files: whether core and plugin files match WordPress.org’s copies (Open Files).
  • Unusual for this site: failed sign-ins or task timing far outside the last 30 days.
  • Activity: the latest log entries, with Open the log.
  • Agents: whether an AI assistant is connected or a request is waiting.

The Findings screen

BetterShield › Findings opens with the same score band as the Overview.

  • Status chips, each with a count: Open (the default), Snoozed, Fixed, Not applicable and All.
  • Search findings matches titles and areas within the chosen status.

Findings are grouped by area: Access, Exposure, Updates & extensions, Server and Configuration. The area with the most serious finding comes first; rows run from most to least serious.

Note: No published-advisory data source is connected in this version, so the report does not say whether an installed version has a known vulnerability. The Findings screen says so rather than showing it as clean.

What each finding shows

Each row shows the title, a severity chip, the points it costs, its area and First seen (or Resolved for a fixed finding). If the latest audit could not evaluate the check, the row says it shows the earlier result.

Explain opens four facts:

  • Why it matters
  • What could break if you act on it
  • Effect on the score
  • Evidence, with when it was Last checked

With an AI provider connected, Explain this in plain language rewrites the finding from that evidence.

Actions

ActionWhat it doesWhy it matters
Apply fixApplies the one-click fix straight away. Undo it from Protect › Hardening.Closes the gap and lifts the score.
Not applicableMoves the finding to Not applicable, out of the score. Put back in the report returns it.For a finding that will never apply here.
Remind me laterIn 7 days or In 30 days. The finding stays open, still counts and moves to Snoozed, marked “Snoozed until date, or until it gets worse”. Show it now brings it back early.For a known, temporary reason to wait.
Run auditRuns every check again. A finding that now passes moves to Fixed.Confirms a change you made by hand.

A finding without a one-click fix links to the screen that handles it instead, where there is one, such as Open Users or Open the file report.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield