WordPress security for agencies and the sites they look after
BetterShield runs on each client site. A free hub shows every site’s score and findings in one place, WP-CLI and a settings file roll out one standard, and each site keeps its own record of who changed what.
What actually goes wrong
Three things that go wrong when one team looks after many sites.
-
Every site is checked one at a time
Each client site has its own dashboard and its own sign-in. Finding the one that needs you means opening each in turn, so the quiet ones get looked at least.
-
Set-ups drift apart
Sites are set up by different people at different times. Without a standard you can copy, one site has two-factor and login limits and the next has neither.
-
Many hands, no record
Your team, the client and anyone else with a login work on the same site. When a plugin is switched off or a new administrator appears, nobody can say who did it.
How BetterShield helps agencies and freelancers
The tools for looking after many sites are in the free plugin. The score, findings and fixes are still worked out on each site, and nothing on a site waits on the hub.
-
Every client site in one free hub
BetterShield Hub is free and optional. Connect each site from its own BetterShield › Hub screen and approve it on that site’s consent page. See every score and finding in one place, hear when a site goes down or its grade drops, and invite your team.
BetterShield Hub guide -
WP-CLI for scripted rollouts
Eleven
WP-CLI commands guidewp bettershieldcommands cover audits, findings, hardening, activity, recovery, file checks and settings, using the same code as the dashboard. A change names an account with--user, and the log records it as coming through WP-CLI. -
One settings file for every site
Export settings on Settings › General writes hardening, password, sign-in, two-factor, passkey, alert and agent settings to a file. Import a settings file on the next site shows a plan first, and each setting it changes appears under Put a settings change back.
General settings guide -
A record of who did what, on each site
Sign-ins, account and role changes, and plugin, theme and core changes, with who and when. Each row names the account or an agent, and notes via WP-CLI. Filter, search and export to CSV, with 30 days of history.
Activity log guide -
A multisite network in one table
On a network, BetterShield › Network lists every site’s score, grade and open findings. Require two-factor across the network and Passkey-only roles across the network set a floor once, and a network recovery link pauses enforcement on every site for an hour.
Multisite network guide -
One assistant, one site or all of them
Connect an assistant to one site under Agents › Connect, read-only to begin with. Or connect it to BetterShield Hub once and ask across every site in your workspace. Either way, a change goes site by site and needs that site’s own confirmation.
AI assistant guide
6 ways people use it
Each one says when it applies and what to set up, or what to ask your assistant for.
- Agency teams
Take on a new client site
A client hands over a site, and you want it on your usual footing before anything else.
- When
- You have just taken a site on and installed BetterShield.
- Setup
- In Quick Setup, choose Me and a team under Who signs in to this site?, then add your agency’s address with Add another email so alerts reach you too. Apply the safe fixes it offers, which cannot lock anyone out. Require two-factor for Administrators is offered on the next step.
- Technical leads
Roll out one standard to every site
Once one site is set up the way you like, the rest should match it.
- When
- Several sites should have the same sign-in limits, two-factor rules and fixes.
- Setup
- On the finished site, press Export settings under Settings › General. On the next, Import a settings file shows a plan, and Make these 4 changes (the button counts the plan) applies it. Over WP-CLI,
wp bettershield settings importshows the same plan until you add--apply.
- Developers
Check every site from a script
Updates and backups already run from the command line, and security can join the same run.
- When
- You script maintenance across sites and want a check that fails when a site slips.
- Setup
wp bettershield audit --fail-under=80 --fail-on=highexits non-zero when the score is under 80 or a high or critical finding is open.wp bettershield integrity scan --fail-on-changesdoes the same when a file differs, andwp bettershield activity --format=csvexports the log.
- Freelancers
See the whole portfolio from one screen
You look after a handful of sites on your own and cannot open each one every day.
- When
- You want to know which site needs you first, and when one goes down.
- Setup
- On each site, open BetterShield › Hub, choose Read this site only if nothing should change from outside, and press Connect to BetterShield Hub. Approve it on the site’s own consent page. Disconnect there ends it at once.
- Account managers
Find out who changed what
Your team, the client and anyone else with a login all work on the same site.
- When
- A plugin was switched off or an account turned up, and the client asks who did it.
- Setup
- Open Activity › Site activity and search for the plugin or account, or filter by Who. Everything from this person narrows the log to one account, and Export CSV gives the client the rows.
- Agency owners
Keep the client in the loop
The people who pay for the site rarely sign in, but they want to know it is looked after.
- When
- A client asks to hear how their site is doing.
- Setup
- Add the client under Where alerts go on Settings › Email alerts. They get the weekly summary, which arrives on quiet weeks too, and high or critical events as they happen. BetterShield Ultra, the separate paid add-on, adds a scheduled client report, weekly or monthly.
The exact prompts to use
Connect your assistant to a client site under Agents › Connect, then paste any of these into Claude, ChatGPT or another assistant. The first two only read. The last two need the second switch on, and anything heavier than a fix with an undo waits for your yes.
Connect an AI assistant-
The monthly client check-up
Read-onlyUsing BetterShield, read this site’s security score, grade and open findings, and list any checks that could not run. Then write a short summary a client could read: where the site stands, and the three findings most worth acting on, with what could break if we act. Do not change anything.
-
Who can change this site
Read-onlyUsing BetterShield, list every account on this site with its role, and tell me which roles must use two-factor. Then read the activity log for the last 30 days and show me every account created or deleted, role changed and password reset requested, with who did it and when.
-
Bring this site up to our standard
Can make changesUsing BetterShield, read which hardening fixes are on and the login protection settings. List the fixes that are still off, with what each would change. Apply the ones that can be undone right away. For anything that changes how people sign in, show me the plan and wait for my yes.
-
After a maintenance round
Can make changesUsing BetterShield, show me which core and plugin files no longer match their official copies, any open incidents, and every plugin or theme the activity log shows was installed, updated, or switched on or off today. If a changed file can be put back, show me the plan before you do it.
Or just ask your AI
BetterShield has an MCP server built in, off until you turn it on. Connect Claude, ChatGPT, Cursor, Codex or another assistant, and it can read your site’s security through 18 read-only abilities, which change nothing.
Changing is a second switch, off by default. With it on, a fix with an undo is applied straight away, and a change to how people sign in waits for you to agree in the conversation. Every call is recorded.
Never possible through a connection: creating accounts or credentials, changing recovery, two-factor or alert settings, lifting lockouts, or deleting log rows.
Connect an AI assistant See what assistants did on Agent activityI am writing this month’s note for the client. Where does the site stand, and what changed?
Used Get security posture → score 87 · grade B · 3 open findings
Used Query activity → last 30 days · 4 plugin updates · 1 role change
Used Get integrity status → core and directory plugins match
The site is at 87, a B, with three open findings, and its files match the official copies. The log shows four plugin updates and one account made an administrator on the 14th by the client’s own account, which is worth confirming with them. One finding has a fix with an undo, so I can apply it now.
Used Apply a protection → Send security response headers · undo kept
Frequently asked questions
Is BetterShield Hub free, and do I need it?
The hub is free and optional, and everything in BetterShield works without it. It works with the free plugin from WordPress.org, so you do not need Ultra to use it. Each site needs BetterShield 1.1.0 or newer.
What can the hub change on a client site?
What you allow when you connect. Read this site only lets it see the score, findings and a few security views, such as administrators by display name and role. Read this site and apply fixes that can be undone also lets it apply and undo fixes, and a change to how people sign in, or taking a protection off, waits for a person to agree each time. Every change the hub makes is recorded in the site’s activity log.
How do I end the hub’s access to a site?
On the site, press Disconnect on BetterShield › Hub, and every hub connection there ends at once. Revoke, under Connected apps on Agents › Connect, ends it too. Removing a site inside the hub does not end the connection.
Can I copy one site’s settings to my other sites?
Yes. Export settings on Settings › General writes a file, and Import a settings file on another site shows a plan before anything changes. Two-factor enrollments, sessions, the recovery link and alert recipients stay behind. The file describes your block lists and sign-in address, so keep it private.
What happens when I copy a client site to staging?
When the site’s address or the folder it runs from changes, the Overview asks whether it is a staging copy or a move. A staging copy mutes alerts and refuses the hub’s connection on that copy only, so nothing about it is mistaken for the live site. One Undo puts it all back.
Do I need BetterShield Ultra to look after client sites?
No. The hub, WP-CLI, settings export and multisite tools are all free. BetterShield Ultra is a separate, paid add-on for people who look after sites for others, with extras such as a scheduled client report, alerts in Slack, at a webhook or in a syslog collector, temporary access that ends on its own and 90 days of activity history. Its yearly licenses differ only in how many sites they cover: 1, 5, 25 or 100.
Keep reading
- Guide
Connect a site to BetterShield Hub
Connect a WordPress site to BetterShield Hub: choose read-only or read-and-fix, approve it on the site’s own consent page, and disconnect at any time. - Guide
WP-CLI commands
Every wp bettershield command in BetterShield 1.1.0, with its options and an example: audit, findings, hardening, activity, recovery, files and settings. - Guide
Run BetterShield on a multisite network
Use BetterShield on WordPress multisite: network activation, the Network screen, rules set for every site, and what each site keeps for itself.
Close the open doors today
Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.
Requires WordPress 6.7 or newer and PHP 8.0 or newer.