WordPress security for bloggers and the people who write with them
BetterShield looks after the accounts that can publish, the comment form anyone can use, and what the site tells any visitor about itself, such as usernames and its WordPress version. It does not sort spam or judge what anyone writes.
What actually goes wrong
Three things that go wrong on sites with several writers and open comments.
-
Every writer’s account can publish
Editors and authors sign in to the same dashboard you do, and each of their accounts can publish under the site’s name. Unless you add a second step, each one rests on a password someone else chose.
-
The comment form is open to anyone
Anyone can leave a comment, and so can a script. Scripts post faster than anyone types, often in bursts from one place, and someone has to read through comments nobody wrote by hand.
-
A public site says more than it needs to
Out of the box, WordPress can hand a visitor your usernames, name its own version in every page, and accept passwords at
xmlrpc.phpas well as at the sign-in page. Scripts use all three to choose what to try.
How BetterShield helps a blog with several writers
Protection for the accounts that publish, the comment form, and what visitors can learn about the site. It is not a spam filter, and edits to posts are not recorded.
-
Two-factor for every role that publishes
Require two-factor of a role lists every role on the site, so you can tick Editor and Author as well as Administrator. Each account gets a 14-day grace period by default, with a countdown on every dashboard page, and sign-in itself is never blocked. Each person sets it up with any authenticator app, or adds a passkey on an HTTPS site, from their own Profile screen.
Two-factor and passkeys guide -
A hidden bot check and a burst limit on comments
Refuse obviously automated submissions puts an invisible field and a clock on the comment, sign-in and registration forms, and refuses scripts that fill every field or submit within two seconds. With Hold a burst of comments for moderation, when one connection reaches 10 comments within 10 minutes, its comments wait in moderation for the next 30 minutes. Nothing is discarded, moderators are never held, and both are on by default.
Login & Access guide -
Stop showing usernames and the version
Block public user listing hides usernames from the REST API, numbered author links (
Hardening guide?author=1), the users sitemap, embeds and sign-in errors. Stop publishing the WordPress version takes it out of the generator tag and asset addresses. Preview the change lists what each would do before anything changes. Both stay off until you apply them, and each has an undo. -
XML-RPC off, after a look at what uses it
Disable XML-RPC answers
XML-RPC guidexmlrpc.phpwith 403 and stops incoming pingbacks, and leaves the REST API that the block editor works through untouched. Preview the change says whether anything used XML-RPC recently, and Monitor first watches real requests for 1 hour, 24 hours or 7 days before you enforce it. -
A record of who joined and who changed roles
The activity log records sign-ins, accounts created or deleted, role changes, and email and password changes, with who and when, for 30 days. By default, an alert is emailed straight away when an administrator or editor account is created, deleted or given a new email address. Edits to posts, pages and other content are not recorded.
Activity log guide -
A file check for core, plugins and your theme
WordPress core and directory plugins are compared with the copies WordPress.org publishes, every hour and whenever a plugin is installed or updated. Your theme and plugins from outside the directory are watched for changes, and Show the difference shows each changed line in a core or directory plugin file.
File check guide
6 ways people use it
Each one says when it applies and what to set up, or what to ask your assistant for.
- Publishers
Ask every editor and author for a second step
Each account that can publish is a password someone else chose. Two-factor means that password alone no longer opens it.
- When
- More than one person writes or edits, or guest writers have accounts of their own.
- Setup
- Under Protect › Two-Factor, tick Editor, Author and any other role your writers use in Require two-factor of a role, then press Save requirement. Each account gets 14 days by default, and your recovery link is checked first.
- Bloggers
Keep comments open without the bursts
You want readers to comment, and you want the queue to hold what they wrote.
- When
- The moderation queue fills with runs of comments from one source, posted faster than anyone could type them.
- Setup
- Already on: Refuse obviously automated submissions and Hold a burst of comments for moderation, both on Protect › Login & Access. To change the limit, set Allowed before it closes, Counted within (minutes) and Closed for (minutes). New numbers are replayed against the last two days before you save.
- Publishers
When a writer moves on
Writers leave and editors change jobs. Their accounts and sessions stay behind until someone tidies up.
- When
- Someone stops writing for you, or moves from editing to the odd guest post.
- Setup
- On Protect › Login & Access, Who is signed in lists their sessions, and Sign out all their sessions ends them. Agents › Surface shows any application passwords the account holds. Change the role or remove the account under Users as usual, and the activity log records who did it.
- Bloggers
Decide about XML-RPC with evidence
Older publishing apps and pingbacks use XML-RPC, and so do scripts that try passwords.
- When
- Findings lists XML-RPC is enabled, and you are not sure whether anyone still publishes through it.
- Setup
- On Protect › Hardening, press Preview the change on Disable XML-RPC to see recent use, or start Monitor first for up to 7 days. Turning the switch off brings XML-RPC back at once. If you will always need it, mark the finding Not applicable.
- Developers
Give visitors less to go on
An archive answers more questions than it needs to: who writes there, which WordPress version runs it, and how strict browsers should be with it.
- When
- Findings lists publicly listable user profiles, the WordPress version in every page, or missing security response headers.
- Setup
- On Protect › Hardening, press Preview the change on Block public user listing, Stop publishing the WordPress version and Send security response headers, then turn each on. The headers finding names one thing that could break: another site that shows your pages in a frame.
- Developers
Move the sign-in address for quieter logs
Scripts ask for
wp-login.phpby name on site after site, and their failed tries fill the log.- When
- Two-factor and login limits are in place, and you want quieter logs. Moving the address gives that, not a stronger door.
- Setup
- Under Signing in on Protect › Login & Access, apply Change the sign-in address, then Hide the dashboard from visitors so
/wp-admin/does not give the new address away. Keep the address off the site: your recovery link brings back the standard page.
The exact prompts to use
Connect your assistant under Agents › Connect, then paste any of these into Claude, ChatGPT or another assistant. The first two only read. The last two need the second switch on, and anything heavier than a fix with an undo waits for your yes.
Connect an AI assistant-
Who can publish here
Read-onlyUsing BetterShield, list every account on this site whose role is Administrator, Editor, Author or Contributor, by display name and role, and tell me which of those roles must use two-factor today. Then read the activity log for the last 30 days and show me every account created or deleted, role changed or email changed, with who did it and when. Do not change anything.
-
What visitors can learn about the site
Read-onlyUsing BetterShield, read my site’s score, grade and open findings. Explain the ones about user listing, the WordPress version, XML-RPC and security headers: what each is, why it matters and what could break if I act on it. Then check the activity log for any XML-RPC use in the last 30 days. Do not change anything.
-
Hide what visitors do not need
Can make changesUsing BetterShield, describe and then apply “Block public user listing”, “Stop publishing the WordPress version” and “Send security response headers”. If the activity log shows no XML-RPC use in the last 30 days, apply “Disable XML-RPC” too; otherwise tell me what used it and leave XML-RPC working. List what you applied, each with its undo.
-
After a theme or plugin change
Can make changesUsing BetterShield, show me every file the last file check found changed, the theme’s included, and which plugins and themes the activity log shows were installed or updated this week. If a changed core or plugin file can be put back, show me the plan before you do it.
Or just ask your AI
BetterShield has an MCP server built in, off until you turn it on. Connect Claude, ChatGPT, Cursor, Codex or another assistant, and it can read your site’s security through 18 read-only abilities, which change nothing.
Changing is a second switch, off by default. With it on, a fix with an undo is applied straight away, and a change to how people sign in waits for you to agree in the conversation. Every call is recorded.
Never possible through a connection: creating accounts or credentials, changing recovery, two-factor or alert settings, lifting lockouts, or deleting log rows.
Connect an AI assistant See what assistants did on Agent activityFour of us publish on this blog. Is our sign-in in good shape, and should we move the login page?
Used Get effective sign-in factor policies → two-factor required for Administrator
Used List this site’s users and roles → 1 Administrator · 1 Editor · 2 Authors
Used Get security posture → score 84 · grade B · 4 open findings
Only the Administrator role has to use two-factor, so your editor and both authors sign in with a password alone. You can add their roles under Protect › Two-Factor, which I cannot change. One open finding touches sign-in: usernames can be listed publicly, and that fix has an undo, so I can apply it now. Moving the sign-in address gives quieter logs, not a stronger door, so add two-factor first. If you still want the move, I have prepared it as a plan.
Used Apply a protection → Block public user listing · undo kept
Frequently asked questions
Can I require two-factor for editors and authors only?
Yes. Require two-factor of a role lists every role on the site, so tick the ones your writers use and leave Subscriber unticked. Each account gets 14 days by default. The requirement is asked in the dashboard, after the password, so sign-in itself is never blocked. Someone who loses their phone signs in with a backup code, or an administrator turns two-factor off for that account.
Does BetterShield filter comment spam?
No. It does not read what a comment says. On the comment form it adds two things, both on by default: the hidden bot check, which refuses submissions that fill a hidden field or arrive within two seconds, and Hold a burst of comments for moderation, which holds a connection’s comments in moderation for 30 minutes once it reaches 10 within 10 minutes. Nothing is discarded, and moderators are never held.
What does Block public user listing change?
Preview the change lists it before anything changes: the users list leaves the REST API for signed-out visitors, a numbered author link such as ?author=1 sends them to the home page, the users sitemap leaves the sitemap index while posts and pages stay, and embeds of your posts stop naming the author. The sign-in form also answers a wrong password and an unknown username the same way.
Should a blog turn off XML-RPC?
Often, but look first. What could break on the finding names tools that may stop, such as the WordPress mobile app if you publish through it, and turning XML-RPC off also stops incoming pingbacks. Preview the change says whether anything used it recently, Monitor first watches for up to 7 days, and turning the switch off brings it back at once.
Does a new sign-in address make our site safer?
No. Change the sign-in address gives quieter logs, not a stronger door: scripts that ask for wp-login.php by name get a 404, and anyone with the new address meets the same form and the same passwords. The attempt limit (5 failures in 15 minutes by default) and two-factor do the real work. If you move it, add Hide the dashboard from visitors and keep the address off the site.
Does the activity log record edits to posts?
No. It records sign-ins, accounts created or deleted, role changes, email and password changes, password resets, plugin, theme and core changes, and key site settings, with who and when, for 30 days. Edits to posts, pages and other content are not recorded.
Keep reading
- Guide
Set up two-factor sign-in and passkeys
Turn on two-factor sign-in with an authenticator app and backup codes, add passkeys, require them by role, and help a user who lost their device. - Blog
Should you disable XML-RPC in WordPress? How to decide and do it
Should you disable XML-RPC in WordPress? What xmlrpc.php does, what still uses it, and how to preview, watch, apply and undo the change. - Blog
Change WordPress login URL: quieter logs, not a stronger door
How to change the WordPress login URL with BetterShield, what moving wp-login.php really stops, and why limits, two-factor and passkeys still matter.
Close the open doors today
Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.
Requires WordPress 6.7 or newer and PHP 8.0 or newer.