BetterShield

WP-CLI commands

6 min read

Every wp bettershield command in BetterShield 1.1.0, with its options and an example: audit, findings, hardening, activity, recovery, files and settings.

BetterShield adds eleven wp bettershield commands to WP-CLI. They use the same code as the dashboard, and changes are logged as coming through WP-CLI.

Note: A command that changes the site needs --user=<login>, naming an account that can manage BetterShield; the change is recorded against it. Reading needs no user, and recover never asks for one.

The eleven commands:

  • audit: the score, grade and open findings.
  • findings: findings from the last audit.
  • harden: list, preview, apply or undo a hardening fix.
  • activity: the activity log.
  • agents: every ability call on the site.
  • verify_log: the activity log against its daily seals.
  • recover: safe mode, from the terminal.
  • integrity: core and plugin files against the published copies.
  • settings: export or import BetterShield’s settings.
  • vulnerabilities: the vulnerability check’s state. No data source is connected in 1.1.0.
  • diagnostics: a block for reporting a problem.

Audit and findings

wp bettershield audit

Runs the read-only audit and prints the score, grade and open findings by severity.

OptionWhat it doesDefault
--format=<format>summary or json.summary
--fail-under=<score>Exit non-zero when the score is below this whole number, 0 to 100.None
--fail-on=<severity>Exit non-zero when an open finding is at this severity or worse: critical, high, medium or low.None
wp bettershield audit --fail-under=80 --fail-on=high

wp bettershield findings

Lists findings from the last audit, with the ID of the fix where there is one.

OptionWhat it doesDefault
--status=<status>open, snoozed, suppressed, fixed or all.open
--format=<format>table, json, csv or count.table
wp bettershield findings --status=snoozed

Hardening

wp bettershield harden

Lists the hardening fixes, or previews, applies or undoes one.

OptionWhat it doesDefault
[<item>]The fix’s ID. Leave it out to list every fix with its ID and state.List
--dry-runDescribe what applying would do, changing nothing.None
--undoRevert the fix.None
--forceApply a sign-in fix even though the recovery check failed. Recorded in the activity log.None
--<field>=<value>An option the fix takes, such as --slug=<address> for login_url.None
--format=<format>For the list: table, json or csv.table
wp bettershield harden login_url --slug=side-door --user=admin
wp bettershield harden xmlrpc --undo --user=admin

Activity

wp bettershield activity

Shows the activity log, newest first.

OptionWhat it doesDefault
--limit=<number>How many entries, at most 500.40
--area=<area>access, exposure, server, configuration, extensions or plugin.All
--search=<text>Match who did it, what it was done to, or the event name.None
--actor=<token>user:<id>, type:system or type:anonymous.None
--from=<date>, --to=<date>Day range as YYYY-MM-DD, in the site’s time zone.None
--sites=<ids>Multisite only: comma-separated site IDs, or all.This site
--format=<format>table, json or csv. CSV exports every matching row.table
wp bettershield activity --from=2026-08-01 --to=2026-08-15 --format=csv > august.csv

wp bettershield agents

Shows every ability call on the site, from any plugin, newest first. Needs WordPress 7.1.

OptionWhat it doesDefault
--limit=<number>How many entries, at most 200. Not used for CSV.40
--outcome=<outcome>completed, permission_denied, input_invalid, input_not_normalizable, output_invalid, short_circuited, failed or unknown.All
--ability=<name>One ability, by exact name.None
--namespace=<prefix>The ability name’s namespace prefix.None
--entry-path=<path>How the call came in: rest, wp-cli, php, or mcp for an assistant.None
--format=<format>table, json or csv (every matching row).table
wp bettershield agents --outcome=permission_denied

wp bettershield verify_log

Checks the activity log against its daily seals and exits non-zero if a sealed day was altered, removed or could not be read. Seals are written once a day, for finished days.

wp bettershield verify_log

Recovery

wp bettershield recover

Turns on safe mode: every protection pauses and the standard sign-in page answers again. No setting is lost.

OptionWhat it doesDefault
--hours=<hours>How long, 1 to 24.1
--endEnd safe mode now and re-arm every protection.None
--new-linkAlso issue a fresh recovery link and print it once. The previous link stops working.None
wp bettershield recover --hours=4 --new-link

Files

wp bettershield integrity

Compares core and directory-plugin files against the published copies. The first argument is the action.

ActionWhat it doesNeeds a user
status (default)When the check last ran, and the files that differ.No
scanRuns the check now.No
restore --id=<change>Puts the published copy back. The current file goes to quarantine, and an undo token is printed.Yes
suppress --id=<change>Marks a change expected, with an undo token.Yes
unsuppress --id=<change>Reports a marked change again.Yes
undo --token=<undo>Reverses a restore or a marking.Yes
recheck --slug=<folder>Compares a plugin’s open changes against its published version again.Yes
expect --slug=<folder> --version=<version>Shows a plugin’s or theme’s group of changes (--type=theme for a theme). Add --yes to mark them expected together.With --yes

Other options: --format=table or json; --fail-on-changes exits non-zero when any file differs; --strict with it also fails when something could not be checked.

wp bettershield integrity restore --id=12 --user=admin

Settings

wp bettershield settings

Exports BetterShield’s settings as JSON, or imports a settings document. An import only shows its plan until you add --apply.

OptionWhat it doesDefault
<action>export or import.None
[<file>] or --file=<path>The document to write or read. With neither, export prints to the terminal.None
--applyFor import, make the changes.Plan only
wp bettershield settings export posture.json
wp bettershield settings import posture.json --apply --user=admin

Other commands

wp bettershield vulnerabilities

Shows the vulnerability check’s state; check runs it now. In 1.1.0 no data source is connected, so it reports that nothing was checked.

OptionWhat it doesDefault
[<action>]status or check.status
--format=<format>table or json.table
--fail-on=<severity>Exit non-zero when an installed component is named by an advisory at this severity or worse.None
--strictWith --fail-on, also exit non-zero when nothing could be checked.None
wp bettershield vulnerabilities

wp bettershield diagnostics

Prints a block for reporting a problem: how BetterShield is set up, with nothing that identifies the site or anyone on it.

wp bettershield diagnostics

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield