Security for Elementor and other page-builder sites
BetterShield compares the add-ons you installed from WordPress.org with their official copies, watches your theme and premium add-ons for changes, and records every install and update.
What actually goes wrong
Three things that go wrong on sites built with a page builder.
-
Many add-ons, many authors
A builder site often runs the builder, a few add-on packs, a forms plugin and a theme, each from a different author and each updating on its own schedule. Nobody keeps a list of what changed, or when.
-
Premium code has no official copy
WordPress.org publishes checksums for the plugins in its directory. Add-ons bought elsewhere, and themes, have none, so a changed file there looks like every other file unless something recorded what it was before.
-
Code can be edited from the dashboard
WordPress gives administrators plugin and theme code editors in the dashboard. A quick change made there goes straight into the code the site runs, and on a site several people manage, nobody else may know.
How BetterShield helps a page-builder site
Add-ons from the WordPress.org directory are compared with the copies WordPress.org publishes. Premium add-ons and the theme have no such copy, so they are watched for changes, and the report says which is which.
-
Directory add-ons against the official copies
WordPress core and plugins from the WordPress.org directory are compared with the copies WordPress.org publishes, every hour and whenever a plugin is installed or updated. Show the difference shows the changed lines, and Put the official file back keeps your copy in quarantine.
File check guide -
Premium add-ons and the theme, watched
WordPress.org publishes no checksums for premium or custom plugins, or for themes. Their code files are recorded at the first check, and later changes are reported, except an update WordPress itself installed. Premium plugins are named in the report’s note, and a changed file is listed under No official copy to put back, so keep your own backups.
File check guide -
A record of every install and update
The activity log records plugin and theme installs, updates, activations, deactivations and deletions, with who and when. When a plugin from outside the directory updates, it notes which code files the update added or changed. Filter, search and export to CSV, with 30 days of history.
Activity log guide -
Add-ons that stopped getting updates
Findings names directory plugins that WordPress.org has closed, and those with no update there for two years, with the last-updated date the directory gives. It reads nothing into either. Explain says why it matters and what could break, and keeping or replacing the plugin is yours to decide.
Score and findings guide -
The dashboard code editors, switched off
Disable the dashboard file editor removes the built-in plugin and theme code editors from the dashboard. Files stay editable over SFTP and through your host. It is one of Quick Setup’s safe fixes, and the finding The dashboard file editor is enabled has an Apply fix button.
Hardening guide -
See what a content policy would block, first
Find out what a content policy would break sends a report-only policy on front-end pages, so nothing is blocked. What the policy would have blocked names each rule and the origin it would have stopped, most frequent first. Start enforcing this policy is offered only after 7 days with no reports.
Security headers guide
6 ways people use it
Each one says when it applies and what to set up, or what to ask your assistant for.
- Designers
Edit the theme on purpose, and mark it expected
You or a developer changed a template file in the theme by hand, and the file check now reports it.
- When
- Activity › File changes lists theme files under No official copy to put back after work you know about.
- Setup
- Check the path and when it was Noticed, then press Expected. It stops reporting the file as it is now, and a further change is reported again. For a batch, Mark all 12 changes expected… under By plugin and version (the button shows your count) names any added files that can run as code first.
- Developers
Check the add-ons after an update round
The builder, its add-ons and the theme update on their own schedules, sometimes all on the same afternoon.
- When
- After a round of plugin and theme updates.
- Setup
- On Activity › Site activity, choose Updates & extensions to see each install and update with who and when, including the code files an update added or changed in a plugin from outside the directory. Then open Activity › File changes, where Check again closes changes that match the installed version’s published copy.
- Site owners
Decide about an add-on nobody updates
An add-on installed for one page years ago is still active, and nobody remembers why.
- When
- Findings shows An installed plugin is no longer in the WordPress.org directory, or An installed plugin has had no update in the WordPress.org directory for years.
- Setup
- Press Explain for Why it matters and What could break, then check the plugin’s page and its author’s own site. Keeping, replacing or removing it is yours to decide. For a known reason to wait, Remind me later snoozes it for 7 or 30 days.
- Developers
Try a fix before it changes anything
The site depends on plugins you did not write, and you want to know what a hardening fix touches before it is live.
- When
- Before turning on a fix on Protect › Hardening, or under Signing in on Protect › Login & Access.
- Setup
- Press Preview the change: it lists what applying would do and changes nothing. For Disable XML-RPC and four Signing in fixes, Monitor first counts the real requests that would have matched over 1 hour, 24 hours or 7 days, then Enforce reviewed settings. A match is not proof of breakage, and no matches is not proof of safety.
- Site owners
See what your pages load from elsewhere
A page can load fonts, scripts, maps and videos from other addresses, and on a site built from many add-ons nobody has the full list.
- When
- You are thinking about a content policy, or you only want the list.
- Setup
- Turn on Find out what a content policy would break under What browsers are told on Protect › Hardening. Nothing is blocked. Read What the policy would have blocked over a week of normal traffic. Start enforcing this policy unlocks only after 7 days with no reports, and Go back to watching returns to report-only at once.
- Agencies
Hand a client site over with the code editors off
The client gets an administrator account, and the theme and add-ons should stay as you delivered them.
- When
- Before handing over a site, or when someone new is given full access.
- Setup
- Turn on Disable the dashboard file editor under What can run on Protect › Hardening, or keep Turn off the file editor ticked in Quick Setup’s Safe fixes. Then, under Where alerts go in Settings › Email alerts, add your own address beside the client’s, so alerts about an altered file reach you.
The exact prompts to use
Connect your assistant under Agents › Connect, then paste any of these into Claude, ChatGPT or another assistant. The first two only read. The last two need the second switch on, and putting a file back waits for your yes.
Connect an AI assistant-
The add-on check-up
Read-onlyUsing BetterShield, read my open findings and pick out the ones about plugins: closed on WordPress.org, no update in the directory for years, code in the plugins folder that no installed plugin claims, or files that no longer match the official copies. For each, tell me why it matters and what could break if I act on it. Do not change anything.
-
After an update round
Read-onlyUsing BetterShield, read the activity log for the last 7 days and list every plugin and theme installed, updated, activated or deleted, with who did it and when, and any note that an update added or changed code in a plugin outside the directory. Then read the file check and tell me which open changes are in directory plugins and which are in the theme or in plugins with no official copy. Do not change anything.
-
Close the code editors, start the content report
Can make changesUsing BetterShield, check whether “Disable the dashboard file editor” and “Find out what a content policy would break” are on. Turn on whichever is off, tell me how to undo each, and leave anything that changes how people sign in alone.
-
Put a changed add-on file back
Can make changesUsing BetterShield, list the open file changes. For a file in WordPress core or a directory plugin that no longer matches its official copy, show me the plan to put the official file back and wait for my yes. For changes in the theme or in plugins with no official copy, list them by path and change nothing.
Or just ask your AI
BetterShield has an MCP server built in, off until you turn it on. Connect Claude, ChatGPT, Cursor, Codex or another assistant, and it can read your site’s security through 18 read-only abilities, which change nothing.
Changing is a second switch, off by default. With it on, a fix with an undo is applied straight away, and a change to how people sign in waits for you to agree in the conversation. Every call is recorded.
Never possible through a connection: creating accounts or credentials, changing recovery, two-factor or alert settings, lifting lockouts, or deleting log rows.
Connect an AI assistant See what assistants did on Agent activityI updated the builder and five add-ons this morning. Is everything as it should be?
Used Query activity → 6 plugins updated today · 1 note: an update added or changed code in an unlisted plugin
Used Get integrity status → 1 open change in a directory plugin · 2 plugins not comparable
Used Get saved hardening state → Disable the dashboard file editor: off
All six updates are in the log, with who ran them. For the add-on from outside the directory, the log also names the code files its update added or changed. One file in a directory plugin no longer matches its official copy, so read the difference on Activity › File changes first. Two plugins have no official copy, so they are watched for changes instead. The dashboard file editor is still on, and I can turn it off now.
Used Apply a protection → Disable the dashboard file editor · undo kept
Frequently asked questions
Can BetterShield check premium plugins and add-ons?
It watches them, but it cannot compare them with an official copy. WordPress.org publishes no checksums for premium or custom plugins, or for themes, so their code files are recorded at the first check and later changes are reported, except an update WordPress itself installed. Activity › File changes names premium plugins in its note and lists a changed file under No official copy to put back, so restore it from your own backup. When one updates, the activity log notes which code files the update added or changed.
Will a normal plugin update show up as a file change?
Not normally. A directory plugin is compared with the checksums for the version installed, and an update WordPress itself installed is not reported for watched code. If changes remain from the version you had before, Check again under By plugin and version closes the ones that match.
Does BetterShield flag add-ons nobody maintains anymore?
For plugins listed in the WordPress.org directory, yes. Findings names any the directory has closed, and any with no update there for two years, with the last-updated date the directory gives, and reads nothing into either. It asks WordPress.org about a few plugins each day, so on a site with many it takes some days to cover them all. Before you add another, Plugins › Add Plugin shows No update since and the date beside the Install button of a plugin with no update for two years.
Will the content policy report change what visitors see?
No. Find out what a content policy would break sends the policy in report-only mode on front-end pages, so nothing a visitor loads changes, and browsers only report what would have been blocked. Start enforcing this policy is offered only once nothing has been reported for 7 days, and asks you to confirm. Go back to watching returns to report-only at once.
What does turning off the dashboard file editor change?
Disable the dashboard file editor removes the built-in plugin and theme code editors from the dashboard. Files stay editable over SFTP and through your host. If wp-config.php already disables the editor, or on a multisite network, it changes nothing. Preview the change shows what applying would do, and turning the switch off undoes it.
Does BetterShield scan add-ons for malware or known vulnerabilities?
No. It has no firewall, does not scan for or remove malware, and its check against published vulnerability advisories has no data source connected in this version. It compares WordPress core and directory plugins with the official copies, watches the theme and other code for changes, and flags directory plugins that are closed or have had no update for two years.
Keep reading
- Guide
Check your files against the official copies
Compare WordPress core and plugin files with the official WordPress.org copies, put a changed file back, mark changes expected and use quarantine. - Guide
Harden your site with one-click fixes
Preview, apply and undo BetterShield’s 16 hardening fixes, trial some on real requests with Monitor first, and see what each one changes. - Blog
WordPress security headers, explained: what each one does
WordPress security headers in plain words: what each one tells the browser, what it could affect, and how to add HSTS and a content policy safely.
Close the open doors today
Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.
Requires WordPress 6.7 or newer and PHP 8.0 or newer.