BetterShield
All use cases Blogs & publishers

WordPress security for bloggers and the people who write with them

BetterShield looks after the accounts that can publish, the comment form anyone can use, and what the site tells any visitor about itself, such as usernames and its WordPress version. It does not sort spam or judge what anyone writes.

What actually goes wrong

Three things that go wrong on sites with several writers and open comments.

  • Every writer’s account can publish

    Editors and authors sign in to the same dashboard you do, and each of their accounts can publish under the site’s name. Unless you add a second step, each one rests on a password someone else chose.

  • The comment form is open to anyone

    Anyone can leave a comment, and so can a script. Scripts post faster than anyone types, often in bursts from one place, and someone has to read through comments nobody wrote by hand.

  • A public site says more than it needs to

    Out of the box, WordPress can hand a visitor your usernames, name its own version in every page, and accept passwords at xmlrpc.php as well as at the sign-in page. Scripts use all three to choose what to try.

How BetterShield helps a blog with several writers

Protection for the accounts that publish, the comment form, and what visitors can learn about the site. It is not a spam filter, and edits to posts are not recorded.

  • Two-factor for every role that publishes

    Require two-factor of a role lists every role on the site, so you can tick Editor and Author as well as Administrator. Each account gets a 14-day grace period by default, with a countdown on every dashboard page, and sign-in itself is never blocked. Each person sets it up with any authenticator app, or adds a passkey on an HTTPS site, from their own Profile screen.

    Two-factor and passkeys guide
  • A hidden bot check and a burst limit on comments

    Refuse obviously automated submissions puts an invisible field and a clock on the comment, sign-in and registration forms, and refuses scripts that fill every field or submit within two seconds. With Hold a burst of comments for moderation, when one connection reaches 10 comments within 10 minutes, its comments wait in moderation for the next 30 minutes. Nothing is discarded, moderators are never held, and both are on by default.

    Login & Access guide
  • Stop showing usernames and the version

    Block public user listing hides usernames from the REST API, numbered author links (?author=1), the users sitemap, embeds and sign-in errors. Stop publishing the WordPress version takes it out of the generator tag and asset addresses. Preview the change lists what each would do before anything changes. Both stay off until you apply them, and each has an undo.

    Hardening guide
  • XML-RPC off, after a look at what uses it

    Disable XML-RPC answers xmlrpc.php with 403 and stops incoming pingbacks, and leaves the REST API that the block editor works through untouched. Preview the change says whether anything used XML-RPC recently, and Monitor first watches real requests for 1 hour, 24 hours or 7 days before you enforce it.

    XML-RPC guide
  • A record of who joined and who changed roles

    The activity log records sign-ins, accounts created or deleted, role changes, and email and password changes, with who and when, for 30 days. By default, an alert is emailed straight away when an administrator or editor account is created, deleted or given a new email address. Edits to posts, pages and other content are not recorded.

    Activity log guide
  • A file check for core, plugins and your theme

    WordPress core and directory plugins are compared with the copies WordPress.org publishes, every hour and whenever a plugin is installed or updated. Your theme and plugins from outside the directory are watched for changes, and Show the difference shows each changed line in a core or directory plugin file.

    File check guide

6 ways people use it

Each one says when it applies and what to set up, or what to ask your assistant for.

  • Publishers

    Ask every editor and author for a second step

    Each account that can publish is a password someone else chose. Two-factor means that password alone no longer opens it.

    When
    More than one person writes or edits, or guest writers have accounts of their own.
    Setup
    Under Protect › Two-Factor, tick Editor, Author and any other role your writers use in Require two-factor of a role, then press Save requirement. Each account gets 14 days by default, and your recovery link is checked first.
  • Bloggers

    Keep comments open without the bursts

    You want readers to comment, and you want the queue to hold what they wrote.

    When
    The moderation queue fills with runs of comments from one source, posted faster than anyone could type them.
    Setup
    Already on: Refuse obviously automated submissions and Hold a burst of comments for moderation, both on Protect › Login & Access. To change the limit, set Allowed before it closes, Counted within (minutes) and Closed for (minutes). New numbers are replayed against the last two days before you save.
  • Publishers

    When a writer moves on

    Writers leave and editors change jobs. Their accounts and sessions stay behind until someone tidies up.

    When
    Someone stops writing for you, or moves from editing to the odd guest post.
    Setup
    On Protect › Login & Access, Who is signed in lists their sessions, and Sign out all their sessions ends them. Agents › Surface shows any application passwords the account holds. Change the role or remove the account under Users as usual, and the activity log records who did it.
  • Bloggers

    Decide about XML-RPC with evidence

    Older publishing apps and pingbacks use XML-RPC, and so do scripts that try passwords.

    When
    Findings lists XML-RPC is enabled, and you are not sure whether anyone still publishes through it.
    Setup
    On Protect › Hardening, press Preview the change on Disable XML-RPC to see recent use, or start Monitor first for up to 7 days. Turning the switch off brings XML-RPC back at once. If you will always need it, mark the finding Not applicable.
  • Developers

    Give visitors less to go on

    An archive answers more questions than it needs to: who writes there, which WordPress version runs it, and how strict browsers should be with it.

    When
    Findings lists publicly listable user profiles, the WordPress version in every page, or missing security response headers.
    Setup
    On Protect › Hardening, press Preview the change on Block public user listing, Stop publishing the WordPress version and Send security response headers, then turn each on. The headers finding names one thing that could break: another site that shows your pages in a frame.
  • Developers

    Move the sign-in address for quieter logs

    Scripts ask for wp-login.php by name on site after site, and their failed tries fill the log.

    When
    Two-factor and login limits are in place, and you want quieter logs. Moving the address gives that, not a stronger door.
    Setup
    Under Signing in on Protect › Login & Access, apply Change the sign-in address, then Hide the dashboard from visitors so /wp-admin/ does not give the new address away. Keep the address off the site: your recovery link brings back the standard page.

The exact prompts to use

Connect your assistant under Agents › Connect, then paste any of these into Claude, ChatGPT or another assistant. The first two only read. The last two need the second switch on, and anything heavier than a fix with an undo waits for your yes.

Connect an AI assistant
  • Who can publish here

    Read-only

    Using BetterShield, list every account on this site whose role is Administrator, Editor, Author or Contributor, by display name and role, and tell me which of those roles must use two-factor today. Then read the activity log for the last 30 days and show me every account created or deleted, role changed or email changed, with who did it and when. Do not change anything.

  • What visitors can learn about the site

    Read-only

    Using BetterShield, read my site’s score, grade and open findings. Explain the ones about user listing, the WordPress version, XML-RPC and security headers: what each is, why it matters and what could break if I act on it. Then check the activity log for any XML-RPC use in the last 30 days. Do not change anything.

  • Hide what visitors do not need

    Can make changes

    Using BetterShield, describe and then apply “Block public user listing”, “Stop publishing the WordPress version” and “Send security response headers”. If the activity log shows no XML-RPC use in the last 30 days, apply “Disable XML-RPC” too; otherwise tell me what used it and leave XML-RPC working. List what you applied, each with its undo.

  • After a theme or plugin change

    Can make changes

    Using BetterShield, show me every file the last file check found changed, the theme’s included, and which plugins and themes the activity log shows were installed or updated this week. If a changed core or plugin file can be put back, show me the plan before you do it.

Or just ask your AI

BetterShield has an MCP server built in, off until you turn it on. Connect Claude, ChatGPT, Cursor, Codex or another assistant, and it can read your site’s security through 18 read-only abilities, which change nothing.

Changing is a second switch, off by default. With it on, a fix with an undo is applied straight away, and a change to how people sign in waits for you to agree in the conversation. Every call is recorded.

Never possible through a connection: creating accounts or credentials, changing recovery, two-factor or alert settings, lifting lockouts, or deleting log rows.

Connect an AI assistant See what assistants did on Agent activity
Your assistant yourblog.example · changes allowed

Four of us publish on this blog. Is our sign-in in good shape, and should we move the login page?

Used Get effective sign-in factor policies → two-factor required for Administrator

Used List this site’s users and roles → 1 Administrator · 1 Editor · 2 Authors

Used Get security posture → score 84 · grade B · 4 open findings

Only the Administrator role has to use two-factor, so your editor and both authors sign in with a password alone. You can add their roles under Protect › Two-Factor, which I cannot change. One open finding touches sign-in: usernames can be listed publicly, and that fix has an undo, so I can apply it now. Moving the sign-in address gives quieter logs, not a stronger door, so add two-factor first. If you still want the move, I have prepared it as a plan.

Used Apply a protection → Block public user listing · undo kept

Moving the sign-in address would change how people sign in, so it waits as a plan for your yes.
Illustration. The tool names are the ones BetterShield gives your assistant.

Frequently asked questions

Can I require two-factor for editors and authors only?

Yes. Require two-factor of a role lists every role on the site, so tick the ones your writers use and leave Subscriber unticked. Each account gets 14 days by default. The requirement is asked in the dashboard, after the password, so sign-in itself is never blocked. Someone who loses their phone signs in with a backup code, or an administrator turns two-factor off for that account.

Does BetterShield filter comment spam?

No. It does not read what a comment says. On the comment form it adds two things, both on by default: the hidden bot check, which refuses submissions that fill a hidden field or arrive within two seconds, and Hold a burst of comments for moderation, which holds a connection’s comments in moderation for 30 minutes once it reaches 10 within 10 minutes. Nothing is discarded, and moderators are never held.

What does Block public user listing change?

Preview the change lists it before anything changes: the users list leaves the REST API for signed-out visitors, a numbered author link such as ?author=1 sends them to the home page, the users sitemap leaves the sitemap index while posts and pages stay, and embeds of your posts stop naming the author. The sign-in form also answers a wrong password and an unknown username the same way.

Should a blog turn off XML-RPC?

Often, but look first. What could break on the finding names tools that may stop, such as the WordPress mobile app if you publish through it, and turning XML-RPC off also stops incoming pingbacks. Preview the change says whether anything used it recently, Monitor first watches for up to 7 days, and turning the switch off brings it back at once.

Does a new sign-in address make our site safer?

No. Change the sign-in address gives quieter logs, not a stronger door: scripts that ask for wp-login.php by name get a 404, and anyone with the new address meets the same form and the same passwords. The attempt limit (5 failures in 15 minutes by default) and two-factor do the real work. If you move it, add Hide the dashboard from visitors and keep the address off the site.

Does the activity log record edits to posts?

No. It records sign-ins, accounts created or deleted, role changes, email and password changes, password resets, plugin, theme and core changes, and key site settings, with who and when, for 30 days. Edits to posts, pages and other content are not recorded.

Keep reading

All use cases

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield