BetterShield
All use cases AI assistants

WordPress MCP security where you decide what the assistant touches

BetterShield has a built-in MCP server, so Claude, ChatGPT, Cursor or Codex can read your site’s security from the site itself. Reading and changing are separate switches, both off until you turn them on, and anything heavier than a small fix with a way back waits for your yes.

What actually goes wrong

Three things that go wrong when an AI assistant meets a live site.

  • An assistant without the facts guesses

    Without a connection, an assistant can only answer from what you paste into the chat. Settings and findings sit on many screens, so the answer is only as good as what you copied across.

  • Reading and changing come as one decision

    Letting an assistant read a site is a small decision. Letting it change a live site is a bigger one. When both come with one switch, you give it more than you meant, or nothing at all.

  • The chat is the only record

    Once an assistant can call tools on your site, you need to know what it ran and what it was refused. A conversation can be closed or lost, and it is not a record the site keeps.

How BetterShield helps you work with an AI assistant

A connection you open one switch at a time, clear limits on what it can read and change, and a record the site keeps.

  • A built-in MCP server, off until you turn it on

    Your assistant connects to your site’s own address. Three steps to a connected assistant, under Agents › Connect, holds three switches, all off by default: reading, changing and the connection itself. Until Let my agent read security information is on, nothing is offered to agents.

    AI assistant guide
  • 18 read-only abilities that change nothing

    They run as the account that connected the assistant: the score, grade and findings with explanations, which fixes are on, the activity log and agent activity, incidents, the file check, and users and roles by display name. Login settings come as counts, never addresses, and no file contents or connector keys are returned.

    WordPress MCP guide
  • Small fixes now, heavier ones by plan

    With the second switch on and a credential that may change the site, seven fixes with a way back apply directly, such as Disable XML-RPC and Stop publishing the WordPress version. The six Signing in fixes, taking any fix off and putting a changed file back come as a plan you agree to in the conversation. A plan expires after 15 minutes.

    Hardening guide
  • What stays yours, whatever the switches say

    No assistant can make an account or credential, change your recovery options, weaken two-factor or alerting, lift a lockout, remove log rows, or write wp-config.php or .htaccess. Three fixes that write files on your server stay your own switch, and changes stop at 5 of one kind and 30 plans an hour, refused rather than queued.

    AI assistant guide
  • A record of every call

    Every tool call over the connection is written to the activity log. On WordPress 7.1 or newer, Record what agents do on this site, on by default, also lists every ability call from any plugin on Activity › Agent activity, refused ones included, with the account, how it came in and the outcome. Inputs are kept only as a digest.

    Agent activity guide
  • One AI connection for many sites

    BetterShield Hub is free and optional. Connect each site from its own BetterShield › Hub screen, connect your assistant to the hub once, and it can look across every site in your workspace. A change still goes site by site, and a change to how people sign in, or taking a protection off, waits for a person to agree.

    BetterShield Hub guide

6 ways people use it

Each one says when it applies and what to set up, or what to ask your assistant for.

  • Site owners

    Ask which finding to fix first

    You want a plain answer about your site’s security without opening every screen, and without letting anything change yet.

    When
    After the first audit, or when the score drops.
    Setup
    Under Agents › Connect, turn on Let my agent read security information and Let an assistant connect to this site, click Connect, and follow Set up your assistant for your app. With the second switch off, the assistant reads and changes nothing. Test connection makes one real call to check it.
  • Site owners

    Let it apply the small fixes

    Some findings have a fix that is small and easy to take back, and you would rather agree once than click through each one.

    When
    Your assistant has read the findings and you are happy with what it found.
    Setup
    Turn on Let agents act: changes that can be undone right away, anything heavier once you agree. A credential issued while it was off stays read-only, so press Rotate for one that may change the site. Each fix it applies is logged, and taking one off again comes as a plan.
  • Developers

    See what else can reach your site

    Other plugins register abilities for agents too, and BetterShield’s switches govern only its own tools.

    When
    You add a plugin that offers abilities to agents, or before you connect an assistant at all.
    Setup
    Open Agents › Surface. Registered abilities lists every ability any plugin offers, and Open to lower roles narrows the list. One that writes, is reachable over REST and is open to lower roles becomes a finding.
  • Agencies

    One conversation across client sites

    You look after several sites and want to know which needs attention first, without signing in to each one.

    When
    A weekly look across the sites you look after, or after a busy week of updates.
    Setup
    Connect each site from its own BetterShield › Hub screen and approve it there, choosing Read this site only for a client who wants no changes. Then connect your assistant to BetterShield Hub once.
  • Site owners

    Check what an assistant did

    You let an assistant work on the site and want to see exactly what it ran, and what it was refused.

    When
    After a session with your assistant, or when an alert says an agent changed something.
    Setup
    Open Activity › Agent activity and set Came through to MCP. Refused calls are highlighted, and Everything this account did narrows the list to one account. With alerts on their defaults, you also get an alert when an assistant connects and when an agent changes something on its own.
  • Agencies

    Show a client what the assistant did

    A client wants to know what an assistant ran on their site, refused calls included.

    When
    At a monthly report, or whenever a client asks.
    Setup
    Activity › Agent activity has no export, so run wp bettershield agents --format=csv for every matching row, or add --outcome=permission_denied for the refused calls only. Recording needs WordPress 7.1.

The exact prompts to use

Connect your assistant under Agents › Connect, then paste any of these into Claude, ChatGPT, Cursor or Codex. The first two only read. The last two need the second switch on and a credential that may change the site, and anything heavier than a fix with a way back waits for your yes.

Connect an AI assistant
  • Where to start

    Read-only

    Using BetterShield, read my site’s security score, grade and open findings, and which hardening fixes are already on. Tell me the three findings worth fixing first and why, which of them have a fix, and what could break if I act on each one. Do not change anything.

  • What agents can do, and what they tried

    Read-only

    Using BetterShield, read the agent surface and list every ability, from any plugin, that is not read-only, is reachable over REST and is open to low-privilege accounts. Then read agent activity and show me every refused call, with the ability, the account it ran as, how it came in and when.

  • Apply the small fixes

    Can make changes

    Using BetterShield, list the hardening fixes that are still off and what each would change. Apply the ones that can be undone right away and tell me what you applied. For anything that changes how people sign in, show me the plan and wait for my yes.

  • Take a fix off, by plan

    Can make changes

    I need XML-RPC again for an app I use. Using BetterShield, show me the plan to take “Disable XML-RPC” off, including what it would allow again and whether it can be put back. Wait for my yes before you go ahead.

What a conversation looks like

One request, three outcomes: the assistant reads the score first, applies the two fixes that have a way back, and holds the change to how people sign in as a plan that waits for your yes.

A plan expires after 15 minutes, and every call the assistant makes over the connection is written to the site’s activity log.

Connect an AI assistant See what assistants did on Agent activity
Your assistant yoursite.example · changes allowed

Fix the small things in my site’s security, and hide the dashboard from visitors while you are at it.

Used Get security posture → score 90 · grade A · 2 open findings

Two findings are open: XML-RPC is enabled, and the WordPress version is published in every page. Both have a fix with a way back, so I am applying them now. Hiding the dashboard changes how people sign in, so that one waits for your yes.

Used Apply a protection → Disable XML-RPC · undo kept

Used Apply a protection → Stop publishing the WordPress version · undo kept

Used Propose a protection, or taking one off → Hide the dashboard from visitors · changes signing in · expires in 15 minutes

Signed-out visitors would get a 404 at /wp-admin/ instead of the sign-in form. The plan is ready for your yes.
Illustration. The tool names are the ones BetterShield gives your assistant.

Frequently asked questions

Which AI assistants can connect to BetterShield?

Set up your assistant has steps for Claude, Claude Desktop, ChatGPT, Cursor and Codex, and other MCP assistants can use the same address. Claude and ChatGPT need pretty permalinks (Settings › Permalinks).

Can an AI assistant change my site without asking?

Only as far as you allow. Changing is a second switch, off by default, and a credential can be issued read-only whatever the switches say. With changes on, seven fixes with a way back apply directly and are logged. The six Signing in fixes, the six-month or all-subdomains form of Tell browsers to refuse plain HTTP, taking any fix off and putting a changed file back come as a plan you agree to in the conversation.

Where do I agree to a change?

In the conversation. The plan says what would change and whether it can be put back, and your assistant is told to show it to you and act only after you agree. The plan expires after 15 minutes. Plans from other callers, such as WP-CLI, wait under Agents › Requests, where Allow once allows that single change and Withdraw cancels it. A sign-in change also needs your recovery link verified within the last day (Protect › Recovery).

What can an assistant never do through BetterShield?

Make an account or credential, change your recovery options, weaken two-factor or alerting, lift a lockout, remove log rows, or write wp-config.php or .htaccess, whatever the switches say. Agents › Permissions lists these under What stays yours. Stop PHP running in uploads, Stop uploads directories listing their contents and Hide sensitive files from visitors are never applied by an assistant either.

Can an assistant see passwords or email addresses?

No. Users come by display name and role, without email addresses or login names, and AI connector keys only by where they are stored. Session times carry no tokens or IP addresses, login settings come as counts, and file contents are never returned.

How do I end a connection?

Turn off Let an assistant connect to this site to pause it without revoking anything. Rotate issues a new credential, and the old one stops working at once. Disconnect ends the credential and every app that signed in through the browser, and Revoke, under Connected apps, ends one app. A new WordPress password does not end a connection.

Keep reading

All use cases

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield