Membership site security for many members and a few staff
BetterShield looks after the accounts on a membership or course site: login limits and a hidden bot check on WordPress’s sign-in and sign-up forms, two-factor for the staff who run it, passkeys any member can add, and a record of who was given which role.
What actually goes wrong
Three things that go wrong on membership and course sites in particular.
-
Sign-up and sign-in are open to everyone
A membership or course site asks people to make an account. The same forms are open to scripts that make throwaway accounts or guess passwords, and the real members are mixed in with them.
-
A few staff accounts hold the keys
Most accounts belong to members who sign in to read, learn or take part. A handful of staff accounts can change courses, members and settings, and unless you add a second step, a password is all that stands in front of them.
-
A role change is easy to miss
New accounts arrive all the time, and nearly all of them are members. One of them quietly given a staff role, or a change to who can register and which role new sign-ups receive, looks like any other account change, and it can sit for weeks before anyone looks.
How BetterShield helps a membership or LMS site
Protection for the accounts and roles behind the site, on WordPress’s own sign-in, sign-up and dashboard. A few protections start at activation, and nothing that changes how people sign in is switched on until you choose it.
-
Login limits that never lock the account
Pause sign-in after repeated failures counts wrong passwords. By default, 5 failed sign-ins in 15 minutes pause that connection for 15 minutes, and the account keeps working from everywhere else. If the attempts named a real account, its owner is emailed an unlock link.
Login & Access guide -
A hidden bot check and limits on sign-up
Refuse obviously automated submissions puts an invisible field and a clock on the WordPress sign-in, registration and comment forms, and people see nothing. Slow repeated sign-ups refuses further WordPress sign-ups from one connection after 8 in an hour, for an hour. Both are on from activation.
Login & Access guide -
Two-factor for the staff who run the site
Require two-factor of a role asks the staff roles you tick to set it up, with a 14-day grace period by default. It is asked in the dashboard after the password, so sign-in is never blocked, and your recovery link is checked before a role is added.
Two-factor and passkeys guide -
Passkeys and devices on every profile
Anyone signed in can set up two-factor, add passkeys and see Where you are signed in on their own Profile screen, with Sign out everywhere except this device. For the roles that hold the most, Sign in with a passkey only stops a password working once that account holds a passkey.
Two-factor and passkeys guide -
A record of who was given which role
The activity log records sign-ins, accounts created, role changes, changes to what a role may do, and changes to who can register and the default role, with who and when, for 30 days. Giving someone a role that can manage settings or users, or changing open registration or the default role, emails you straight away.
Activity log guide -
A way back in for the owner
Your recovery link pauses the sign-in protections for one hour and changes no setting. For an emergency, Lock the site down refuses sign-ins from every account that cannot manage the site, members included, and stops registrations, while the front end keeps working.
Getting back in guide
6 ways people use it
Each one says when it applies and what to set up, or what to ask your assistant for.
- Site owners
Put a second step in front of the dashboard
Staff accounts can change courses, members and settings. With two-factor, a password alone no longer opens them.
- When
- More than one person signs in to manage content, members or settings.
- Setup
- Under Protect › Two-Factor, tick your staff roles in Require two-factor of a role and press Save requirement. Each account gets 14 days to set it up by default, and your recovery link is checked first.
- Course creators
Open enrollment without the bot sign-ups
A new course or cohort brings a rush of new accounts, and scripts arrive with the people.
- When
- You open registration and expect many sign-ups in a short time.
- Setup
- Already on: Refuse obviously automated submissions and Slow repeated sign-ups, under Protect › Login & Access. If a class signs up together from one school’s fixed address, add it to Always allowed, which form limits never hold. Release now under Lockouts ends a closure early.
- Community managers
Help a member who has been paused
A member who forgot their password tries a few times and is asked to wait.
- When
- A member writes in to say the sign-in form told them there were too many failed sign-ins.
- Setup
- The pause ends on its own, 15 minutes by default. Because the attempts named their account, the member’s email address gets an unlock link whose Clear the lockout button ends it, and you can press Release now under Lockouts on Protect › Login & Access.
- Community managers
When a member sees a sign-in they do not know
A member thinks someone else has been using their account.
- When
- A member reports a device or place they do not recognize.
- Setup
- On their Profile screen, Where you are signed in lists each device, and Sign out everywhere except this device ends the others. From your side, Who is signed in on Protect › Login & Access has Sign out all their sessions.
- Course creators
Cap the devices on one account
One membership can end up signed in on more devices than one person uses.
- When
- You want each account signed in on only a few devices at a time.
- Setup
- Set Sessions per account under Sessions on Protect › Login & Access. When an account signs in past the cap, its oldest session signs out. It is 0, no cap, by default, and is unavailable where another plugin replaced WordPress’s session storage.
- Site owners
Keep members out of the dashboard
Members sign in to read, learn or take part, and have no work to do in the dashboard.
- When
- Your member role has no reason to see dashboard screens.
- Setup
- Under Signing in on Protect › Login & Access, Keep low-privilege accounts out of the dashboard sends the role you choose (Subscriber is preselected) from
wp-adminto the front page, except their profile. Monitor first watches real requests for up to 7 days before you enforce it, and it never applies to a role that can manage the site.
The exact prompts to use
Connect your assistant under Agents › Connect, then paste any of these into Claude, ChatGPT or another assistant. The first two only read. The last two need the second switch on: a fix with an undo is applied right away, and a sign-in change waits for your yes and a recovery link checked within the last day.
Connect an AI assistant-
The sign-in check-up
Read-onlyUsing BetterShield, read my login protection settings and my two-factor and passkey role rules. Tell me whether the attempt limit and the hidden bot check are on and at what numbers, whether a session cap or an idle timeout is set, and which roles must use two-factor or passkeys. Do not change anything.
-
Who was given a role
Read-onlyUsing BetterShield, read the activity log for the last 30 days and list every role change, every role given or taken away, and every change to what a role may do, with who did it and when. Then tell me whether anyone changed who can register or the default role for new accounts. Do not change anything.
-
Before a new course opens
Can make changesUsing BetterShield, read my security score and open findings, check that sign-in limits and the hidden bot check are on, and list the hardening fixes that are still off with what each would change. Apply the ones that can be undone right away. For anything that changes how people sign in, show me the plan and wait for my yes.
-
Keep members out of the dashboard
Can make changesUsing BetterShield, plan “Keep low-privilege accounts out of the dashboard” for the Subscriber role. Show me exactly what it would change and whether it can be put back, then wait for my yes before you apply it.
Or just ask your AI
BetterShield has an MCP server built in, off until you turn it on. Connect Claude, ChatGPT, Cursor, Codex or another assistant, and it can read your site’s security through 18 read-only abilities, which change nothing.
Changing is a second switch, off by default. With it on, a fix with an undo is applied straight away, and a change to how people sign in waits for you to agree in the conversation. Every call is recorded.
Never possible through a connection: creating accounts or credentials, changing recovery, two-factor or alert settings, lifting lockouts, or deleting log rows.
Connect an AI assistant See what assistants did on Agent activityWe open enrollment for a new course on Monday. Are sign-in and sign-up ready?
Used Get login protection settings → limit on · 5 in 15 minutes · bot check on
Used Get effective sign-in factor policies → two-factor required for no roles
Used Get saved hardening state → Keep low-privilege accounts out of the dashboard · off
Login limits and the hidden bot check are on. No role has to use two-factor yet, so staff accounts rely on their passwords: you can require it under Protect › Two-Factor, which I cannot change. Keeping members out of the dashboard is off, and it changes how people sign in, so I can only plan it.
Used Propose a protection, or taking one off → Keep low-privilege accounts out of the dashboard · Subscriber · plan ready
wp-admin to the front page, and keep their own profile screen. The plan is ready for your yes. Frequently asked questions
Can I require two-factor for every member?
Require two-factor of a role is asked in the dashboard, after the password: a countdown on dashboard pages, then the setup screen once the grace period ends. Sign-in is never blocked and the front end keeps working, so a member who never opens the dashboard is not stopped by it. Use it for your staff roles. Members can still set up two-factor themselves on their own Profile screen.
Does the hidden bot check cover my membership plugin’s own forms?
It is added to the WordPress sign-in and registration forms, the comment form and a store’s account forms. BetterShield has no settings for any particular membership or course plugin, so a sign-in or sign-up form another plugin draws may not carry it, and a form without it is never refused for that. The login limit reaches further: it counts wrong passwords wherever WordPress itself checks one.
What happens when a member gets their password wrong too many times?
By default, 5 failed sign-ins in 15 minutes from one connection pause sign-in from that connection for 15 minutes, longer if it happens again within a day. The account itself is not locked, and if the attempts named a real account, its owner is emailed an unlock link with Clear the lockout. Release now, under Lockouts, ends a pause early.
Can members sign in with a passkey?
Yes. Anyone signed in can add a passkey on their own Profile screen, up to 10 per account, and passkeys need HTTPS. Once any account has one, the WordPress sign-in page (wp-login.php) shows Sign in with a passkey. A passkey is an extra way in: the password keeps working unless the member’s role is ticked under Sign in with a passkey only.
Does BetterShield flag open registration?
Only when new accounts get a role that can write. Then the audit raises a high finding, “Anyone can register, and new accounts get more than reader access”, cleared by setting the default role to Subscriber under Settings › General or by closing registration. Open registration into a reading role such as Subscriber is not flagged. A change to open registration or the default role is recorded and emailed to you straight away.
Does BetterShield check members’ passwords against known breaches?
Only if you turn on Refuse passwords found in known breaches, which is off by default. It checks new passwords set by people who are signed in, such as a change on the profile screen, and sends Pwned Passwords only the first five characters of a hash. It never affects signing in, and the registration and reset forms are not checked.
Keep reading
- Guide
Set up sign-in protection on Login & Access
Set BetterShield’s login attempt limits, hidden bot check, public form limits, allow and block lists, trusted proxies and session limits. - Blog
WordPress two-factor authentication and passkeys: a setup guide
Set up WordPress two-factor authentication with any authenticator app, add passkeys, require both by role, and help someone who lost their phone. - Guide
Read the site activity log
What the BetterShield activity log records and leaves out, how to filter, search and export it, how long rows are kept, and how daily seals work.
Close the open doors today
Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.
Requires WordPress 6.7 or newer and PHP 8.0 or newer.