BetterShield

Switch from All-In-One Security to BetterShield

4 min read

Bring All-In-One Security’s login lockdown numbers and matching hardening into BetterShield with a preview first, then deactivate the old plugin.

For sites that run All-In-One Security now, or ran it before, and are moving to BetterShield.

BetterShield reads the settings All-In-One Security left on the site and, after a preview, turns the ones it can match into its own. The old plugin is only read, never changed or switched off.

What carries over

Only what is switched on in All-In-One Security is carried. The first row lands on Protect › Login & Access, the rest on Protect › Hardening.

In All-In-One SecurityIn BetterShield
Login lockdown on, with its maximum login attempts, retry time period and lockout time lengthPause sign-in after repeated failures, with Failures allowed, Counted within (minutes) and Pause lasts (minutes)
Disabling file editingDisable the dashboard file editor
Preventing user enumerationBlock public user listing
Removing the WordPress generator meta informationStop publishing the WordPress version
Disabling index viewsStop uploads directories listing their contents
Its pingback firewall for XML-RPCDisable XML-RPC
  • The numbers must fit BetterShield’s range: 3 to 100 attempts, and 1 to 1440 minutes for each time.
  • The import only turns protections on, never off.

What does not carry over, and why

The preview lists each one that is switched on there under Not carried over from, with the reason.

  • Turning off only XML-RPC pingbacks: no one-to-one fix, as Disable XML-RPC turns all of XML-RPC off. Turn it on yourself if nothing on the site uses XML-RPC.
  • A changed sign-in address: not carried in this version. Set it with Change the sign-in address on Protect › Login & Access, where it is checked against a working way back in first.
  • Sign-in attempt limits: held back while All-In-One Security is active and its login lockdown is on, so two plugins never count the same attempts, or when the numbers fall outside the range.

Anything else is neither read nor listed. Two-factor enrollments never travel in an import.

While All-In-One Security is still active

Quick Setup’s Another security plugin is active step has a row per shared job, each starting on All-In-One Security:

  • Login attempt limits, only while its login lockdown is on: Keep All-In-One Security (BetterShield’s own limit goes off) or Use BetterShield.
  • Two-factor: Keep All-In-One Security, so anyone enrolled there signs in as now, or Use BetterShield.
  • Activity log and File change monitoring: Keep both or Use BetterShield only.
  • Login address: a statement that All-In-One Security handles it, and BetterShield’s own option for moving it stays off.
  • Firewall and site scanner: a statement that BetterShield does not run a firewall or a malware scan.

On Protect › Login & Access, Change the sign-in address also warns while All-In-One Security is active, because both can move or hide the sign-in page.

The Overview’s Who does which job card shows the split. Not every overlap is caught, so avoid running sign-in limits or two-factor in both.

Switch over, step by step

  1. Install and activate BetterShield, leaving All-In-One Security active. The first audit changes nothing.
  2. In Quick Setup, choose who keeps each job and press Save choices. Already set up? Run Quick Setup again is on Settings › General.
  3. Go to BetterShield › Settings › General. Under This installation, Move settings between sites lists All-In-One Security as (active) or (not active). A deleted plugin whose settings remain shows as A security plugin that is no longer installed.
  4. Press Preview import. Nothing changes yet. Each fix shows will be applied, already matches, cannot work on this server or was refused, with any warning beside it. Login protection shows will change when your sign-in settings would change.
  5. Read the Not carried over from list, then press Make these 4 changes (the button counts them).
  6. Check the result (below), then deactivate All-In-One Security on the Plugins screen.
  7. If the attempt limits were held back, press Preview import again. With the old plugin inactive, they carry over.

What to check after

  • Each carried fix shows On since, and Pause sign-in after repeated failures shows your numbers.
  • An audit runs straight after the import. Once the old plugin is deactivated, the finding Nothing is limiting sign-in attempts means BetterShield’s limit is off: preview the import again, or switch the limit on.
  • Anyone who used two-factor in the old plugin sets it up again under Protect › Two-Factor.

Undo the import

No single step reverses the whole import. Each change has its own undo:

  • A fix it turned on: switch it off on Protect › Hardening. Files the fix wrote are put back as they were.
  • Sign-in numbers: under Put a settings change back on Settings › General, press Put it back on the Login protection row. It restores only what the import changed there, and asks you to put any newer change to those settings back first.

All-In-One Security itself was never changed.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield