Every free feature, in one plugin.
BetterShield audits your site, explains every finding in plain language, and fixes what it can in one click with your approval. Every fix has an undo that never expires.
Get BetterShield What Ultra adds
No account needed. Requires WordPress 6.7 or newer and PHP 8.0 or newer.
One plugin, every security job
Pick an area to see everything BetterShield does there.
See how it compares with other security pluginsA 54-check security audit
54 read-only checks cover access, exposure, updates, extensions, server settings and configuration. The audit scores your site, and nothing changes until you choose a fix. Not ready to act on a finding yet? Snooze it for 7 or 30 days.
- Idle “Admin” accounts nobody has used in over six months
- User enumeration, XML-RPC, the file editor and the WordPress version on every page
- Missing security headers, an outdated PHP version and weak security keys
- Plugins closed on WordPress.org, or with no update for years
- Installer or database tools left in the web root after a migration
- A domain without SPF, DMARC or CAA records
- Core and plugin files that no longer match the official copies
Each finding explains what it is, why it matters and what could break if you act on it. A check that could not run is never reported as clean.
16 one-click fixes, each with an undo that never expires
Each fix shows what it will change before you apply it, and stays off until you do. Change your mind months later and switch it off in one click. The Quick Setup offers five fixes that cannot lock anyone out.
- Disable XML-RPC
- Disable the dashboard file editor
- Block public user listing (user enumeration)
- Stop PHP running in uploads
- Stop uploads directories listing their contents
- Hide sensitive files from visitors
- Change the sign-in address (custom login URL)
- Refuse application passwords
- Refuse passwords found in known breaches
- Keep low-privilege accounts out of the dashboard
- Hide the dashboard from visitors
- Stop publishing the WordPress version
- Strengthen and rotate the sign-in keys
- Tell browsers to refuse plain HTTP (HSTS)
- Find out what a content security policy (CSP) would break, before you enforce one
- Send security response headers
A fix your hosting cannot support, such as .htaccess rules on a server that is not Apache, cannot be switched on, and the screen tells you why.
Login protection and brute-force defense
By default, 5 failed sign-ins in 15 minutes pause that connection for 15 minutes, doubling with each repeat within a day.
- A hidden bot check on the login, registration, WooCommerce account and comment forms
- Comment bursts wait in moderation, and repeated password resets or sign-ups are paused
- Strong password rules and an optional breached-password check
- An IP and username blocklist, and an allowlist that is never locked out
Two-factor authentication (2FA) and passkeys
For yourself, the roles you choose or your WooCommerce customers.
- Two-factor with any authenticator app and 10 single-use backup codes
- Two-factor required by role, with a 14-day grace period by default
- Passkeys: sign in with a fingerprint, face or device PIN
- Passkey-only sign-in by role, once a working recovery option is in place
Two-factor is never enforced until the app is proven to work, and only the public half of a passkey is stored.
Lockout recovery without FTP
Locked out? Get back in without FTP or a call to your host.
- A single-use recovery link, emailed when you activate BetterShield
- Press its one button and the sign-in protections pause for one hour, with your settings left as they are
- Using a link issues the next one straight away, on the page and by email
- A link you never use stops working after 90 days, with a warning in the last two weeks
- Printed recovery codes are a second way in
Security activity log
Sign-ins, account and role changes, password resets, and plugin, theme and core changes, with who and when.
- Filter, search and export to CSV
- 30 days of history
- Each finished day is sealed, so an edit or deletion opens a high-severity finding
File integrity check against WordPress.org
WordPress core and directory plugins are compared with the official copies WordPress.org publishes, showing exactly which lines changed.
- One click puts the official file back
- The replaced file is kept, never deleted
- Your theme, drop-ins, wp-config.php, .htaccess and other unpublished code are watched for changes
A file that was never compared is never reported as clean.
Incident response and alerts
Related access and file changes are joined into one incident, with signs of an account takeover flagged.
- You review the response plan before anything changes
- BetterShield checks again afterward
- A weekly summary that arrives on quiet weeks too
- High or critical events are emailed on their own
No message ever contains an upgrade prompt.
AI explanations and AI assistants (MCP)
Ask an AI assistant what needs fixing, and get any finding explained in plain language.
- With an AI provider connected under Settings › Connectors (WordPress 7.0 or newer), explain any finding, or ask Explain my audit for a summary
- The MCP server lets Claude, ChatGPT, Cursor, Codex and other assistants read your site’s security through 18 bounded, read-only abilities
- It is off until you turn it on under Agents › Connect
- A second switch, off by default, lets an assistant apply and undo fixes
Never possible through a connection: creating accounts or credentials, changing recovery, two-factor or alert settings, lifting lockouts, or deleting log rows.
BetterShield Hub
An optional dashboard for people who look after more than one site.
More about BetterShield Hub- Connect sites from BetterShield › Hub to see every score and finding in one place
- Apply or undo fixes across sites, each recorded in that site’s activity log
- Alerts when a site goes down or its grade drops
- Invite your team
Everything in BetterShield works without the hub.
Built for agencies and many sites
The tools for looking after sites at scale are in the free plugin.
- WP-CLI commands for audits, findings, hardening, activity, recovery, file checks and settings
- Settings export and import, with a preview and an undo
- Multisite: every site’s score in one table, and two-factor and passkey rules set once for the network
Works alongside your current security plugin
BetterShield works alongside the security plugin you already have, and makes sure the two do not do the same job twice.
- Switching over? It can bring over settings from Kadence Security, All-In-One Security, Really Simple Security or Wordfence
- You see a preview first, with what it could not carry and why
- The other plugin is only read, and the import can be undone
Nothing leaves your site unless you choose it
Out of the box, the only outside services BetterShield contacts are WordPress.org’s own, asked about your files and plugins.
- Usage sharing (asked once in Quick Setup), the breached-password check, your AI provider and the Hub are each off until you turn them on
- The Overview shows the queries and milliseconds BetterShield added to real page views
- No account and no sign-up needed
Looking after sites for others?
Ultra adds two-factor setup at sign-in, trusted devices, branded two-factor screens, Slack, webhook and syslog alerts, a scheduled client report, temporary access that ends on its own and Cloudflare controls. Everything on this page is in the free plugin.
See what Ultra addsClose the open doors today
Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.
Requires WordPress 6.7 or newer and PHP 8.0 or newer.