What BetterShield contacts, and when
Every outside address BetterShield and BetterShield Ultra contact, when, exactly what is sent, and how to turn each optional one off.
Out of the box, BetterShield contacts WordPress.org only, to check your files and plugins. Everything else is off until you turn it on, and there is no account.
Out of the box: WordPress.org
| Service | When | What is sent | How to turn it off |
|---|---|---|---|
| api.wordpress.org | During the hourly file check. Each list is kept for a week; Check now fetches a fresh one. | Your WordPress version and language. | Not optional. |
| api.wordpress.org | Daily, asking whether the directory still lists up to eight of your directory plugins. | One plugin’s slug per request. | Not optional. |
| downloads.wordpress.org | During the file check, on Check again, and whenever a plugin is installed or updated, automatic updates included. | The plugin’s slug and version. | Not optional. |
| core.svn.wordpress.org, plugins.svn.wordpress.org | Only when you press Show the difference or Put the official file back on a changed file (or a restore from WP-CLI or an assistant). | The version and the file’s path. | Do not press them. |
None of these requests carries your site address, email, usernames, keys, file contents or any identifier; they name only BetterShield and its version. Like any connection, they come from your server’s IP address. They never run while a visitor loads a page, and if WordPress.org cannot be reached, the check says it could not run.
Recommended plugins you switch on in Quick Setup come through WordPress’s own installer, from api.wordpress.org and downloads.wordpress.org.
Only if you turn it on
| Service | When | What is sent | How to turn it off |
|---|---|---|---|
| send.wpinsight.com (WPDeveloper usage data) | Only after Get Started in Quick Setup or Share usage data: once then, at most daily after, and on deactivation. | Site address and title, administrator email, WordPress, PHP and web server versions, language, character set and text direction, whether it is multisite, BetterShield’s folder and version, installed and active plugins, your theme and its version, and the report reference. Never anything about visitors, users, sign-ins or findings, and never the full server path. | Turn off Share usage data under Settings › General. |
| api.pwnedpasswords.com (Have I Been Pwned) | Only with Refuse passwords found in known breaches on (Protect › Login & Access), when someone signed in sets or changes a password. | The first five characters of the password’s hash. The comparison happens on your server. Never the password, account, email or site address. | Turn that fix off. |
| Your own AI provider | Only when someone presses Explain this in plain language on a finding, Explain my audit on the Overview, or Explain this on an incident, with a provider connected under Settings › Connectors. | For a finding: its title, severity, description, what could break and its recorded evidence, minus anything shaped like a web or email address, IP address or host name. Explain my audit sends the title, severity and evidence of up to 12 open findings; an incident, its event names and times with accounts and files replaced by placeholders. Never file contents, usernames, keys or your site address. | Do not press them, or remove the provider. BetterShield never sees, asks for or stores the key. |
| BetterShield Hub (hub.bettershield.ai, or the address set under BetterShield › Hub) | Your site never contacts the hub. Pressing Connect to BetterShield Hub sends your browser there once; after you approve, the hub contacts your site. | Your browser carries the site address, a one-time ticket, the access you chose and the address to return to. When the hub signs in, the site tells it its address, site number and BetterShield version. The hub then reads the score, findings and a few security views, and can apply fixes if you allowed it. | Disconnect on BetterShield › Hub, or Revoke under Agents › Connect. |
Assistants you connect under Agents › Connect also call your site; it never calls them.
BetterShield Ultra
| Service | When | What is sent | How to turn it off |
|---|---|---|---|
| api.wpdeveloper.com | When you activate or stop using a license, weekly while a license is active, when WordPress checks for plugin updates, and when Ultra is deleted. | Your license key once entered, the site address, the product details and Ultra’s version, and the site’s environment type. Update checks also send your WordPress and PHP versions. | Stop using this license here on the License tab ends the weekly check. Update checks run while Ultra is active. |
| api.cloudflare.com | Only with a Cloudflare token saved under Settings › Connectors: when you use the Cloudflare tab, and, with Carry sign-in lockouts out to the edge on, when a lockout starts or ends. Never from a visitor’s request. | The token, the zone changes you make, and for a lockout the network range (a /24 or /64, never a full address). | Turn the switch off, or remove the token. |
| Your alert destinations | Only the Slack, webhook or syslog addresses you add on the Alert channels tab: high and critical alerts as they happen, or the activity record for the event classes you choose. | Your site name and address; each event’s type, severity and time; what it was about (for a refused sign-in, the username typed); and the acting account as a number, never a name. Never the visitor’s network, a credential or file contents. | Remove the destination. |
Everything else
- Published vulnerability advisories: no data source is connected in this version.
- Report a problem (Settings › General) sends nothing; you copy it yourself.
- Emails, such as alerts, recovery links and Ultra’s client report, go through your site’s own mail setup.
- Your own site: some checks ask your own web server what a visitor would get, and your domain’s SPF, DMARC and CAA records are looked up daily through your server’s DNS resolver.