BetterShield

Security you can actually read.

BetterShield looks over your WordPress site and tells you what it found, in plain language. You decide what to fix, and you can change your mind afterwards.

A WordPress plugin from WPDeveloper.

The audit

38 checks, grouped by the part of your site they are about

All of them only read. None of them change anything. Every finding explains why it matters and what could break if you act on it, and you get a score you can see the workings of.

  • Access 11

    An account named "admin", the very first account still being an administrator, user profiles anyone can list, open registration into a role that can publish, accounts with real permissions nobody has signed in to for months, application passwords left unused for months, passwords below your own policy, administrator passwords still stored in the older format, sign-in lockouts that are not counting, sign-in limits that cannot be enforced, and a recovery link close to expiring.

  • Exposure 11

    XML-RPC, the dashboard file editor, the WordPress version printed into every page, missing security response headers, files a stranger can download that were never meant to be there, REST routes answering visitors who are not signed in, an agent-callable ability open to low-privilege accounts, scheduled events no code answers, published pages still pointing at plain HTTP, a certificate approaching its expiry, and a published security contact past its own date.

  • Server 4

    HTTPS, a PHP version that no longer gets security fixes, wp-config.php being writable by other accounts on the machine, and whether the folder of kept file copies is sealed off from the web.

  • Configuration 4

    The secret keys in wp-config.php, the default database table prefix, debug output shown to visitors, and a sealed day of the activity log that no longer matches its seal.

  • Updates and extensions 8

    Core and plugin updates waiting, deactivated plugins or themes still sitting on the server, a plugin the WordPress.org directory has stopped listing, known vulnerabilities in the versions you have installed and how old that data is, and whether your files still match the copies WordPress.org publishes.

Two of the checks are graded against where the site is running. Plain HTTP and visible debug output are normal on a laptop and serious on a live site, so BetterShield grades them differently instead of coloring both the same way. It works that out on your own server.

The fixes

15 things you can change in one click

  • Disable XML-RPC
  • Disable the dashboard file editor
  • Block public user listing
  • Stop PHP running in uploads
  • Stop uploads directories listing their contents
  • Hide sensitive files from visitors
  • Change the sign-in address
  • Refuse application passwords
  • Keep low-privilege accounts out of the dashboard
  • Hide the dashboard from visitors
  • Stop publishing the WordPress version
  • Strengthen and rotate the sign-in keys
  • Tell browsers to refuse plain HTTP
  • Find out what a content policy would break
  • Send security response headers

Each one applies on its own and takes effect straight away. Each one has an undo that puts back exactly what was there before, and that undo never expires. If a fix is likely to clash with something you already run — another plugin that moves the sign-in page, or one that keeps rules in the same .htaccess file — you are told before you apply it, not after.

Recovery and history

If you get locked out

When you activate the plugin it emails you a recovery link. Opening that link pauses every BetterShield protection for an hour. No login, no password, no second factor. Nothing is deactivated and no setting is lost.

Each link works once. The page you land on shows you the next one straight away and emails a copy, and you can generate a fresh one from the dashboard at any time — which stops the old one working.

What it records

Sign-ins and failed sign-ins, account and role changes, application passwords, plugin and theme changes, and everything the plugin does itself. Each entry says who did it, what it was, and when. Filter it, search it, export it as CSV.

Entries are written in one batch after the page has already been sent to the visitor, and nothing at all is written during WooCommerce checkout. This release keeps 30 days of history.

Worth saying plainly

What it does not do

There is no firewall and no malware scanning. Doing either of those badly is worse than not doing them, and we would rather say so than pretend otherwise. It can compare your files against the copies WordPress.org publishes and show you exactly what differs, line by line. It makes no claim to recognize malicious code.

How it behaves

The rules it holds itself to

  • Audits only read. Nothing on your site changes unless you ask for it.
  • Every change can be undone, and the undo is permanent.
  • Where a fix has to share a file with your server, it keeps its own marked block in it. Edit that block yourself and it is left alone and reported, never overwritten.
  • The only outside services contacted are WordPress.org's own, and your own AI provider if you connect one. There is no account, and no site address, email, username or key is ever sent.
  • A file put back is never deleted. The version that was there is kept, because it may be the thing you need to look at.
  • The whole diagnosis is free, and there is never an upsell inside a security warning.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.