WordPress security, in plain words
Guides you can act on, and news about BetterShield.
RSS feedAll posts
-
Disable file editing in WordPress with or without DISALLOW_FILE_EDIT
Why to disable file editing in WordPress, how DISALLOW_FILE_EDIT and BetterShield’s one-click fix each do it, what it can affect, and how to put it back.
-
WordPress activity log: what it records and what to look for
A WordPress activity log shows who did what, and when. What BetterShield’s audit log records, how its sealed days work, and what to look for in it.
-
WordPress application passwords: find, limit and revoke them
WordPress application passwords sign tools in without a second factor. How to find unused ones, revoke an application password, and limit the rest.
-
WordPress breached password check: what leaves your site
How BetterShield’s WordPress breached password check uses Pwned Passwords: what leaves your site, which passwords it checks, and what happens to old ones.
-
WordPress hardening: 16 one-click fixes and what each changes
A WordPress hardening checklist in one click: what each of BetterShield’s 16 fixes changes, what it can affect, and which to watch with Monitor first.
-
WordPress user roles security: least privilege without guesswork
WordPress user roles security in practice: the audit checks for risky accounts and roles, two-factor by role, and alerts when an account gains more power.
-
Introducing BetterShield: a free WordPress security plugin
BetterShield is a free WordPress security plugin that runs 54 checks, explains what it finds, and closes the gaps with one-click fixes you approve.
-
WordPress MCP: connecting an AI assistant to your site safely
What a WordPress MCP connection lets an AI assistant read and change, six questions to ask before you connect one, and how BetterShield answers them.
-
Change WordPress login URL: quieter logs, not a stronger door
How to change the WordPress login URL with BetterShield, what moving wp-login.php really stops, and why limits, two-factor and passkeys still matter.
-
Should you disable XML-RPC in WordPress? How to decide and do it
Should you disable XML-RPC in WordPress? What xmlrpc.php does, what still uses it, and how to preview, watch, apply and undo the change.
-
Limit login attempts in WordPress without locking yourself out
How to limit login attempts in WordPress: sensible numbers, pauses that never lock the account, proxy and Cloudflare checks, and a way back in.
-
Locked out of WordPress? How to get back in without FTP
Locked out of WordPress? BetterShield’s recovery link, printed codes, unlock email and WP-CLI get you back in without FTP or a call to your host.
-
WordPress file integrity check: compare with the official copies
A WordPress file integrity check compares core and plugin files with the copies WordPress.org publishes. How BetterShield runs one, and what to do next.
-
The WordPress security checklist: 54 checks, explained
A practical WordPress security checklist: the five areas BetterShield audits, the checks that matter most in each, and what to do about every finding.
-
WordPress security headers, explained: what each one does
WordPress security headers in plain words: what each one tells the browser, what it could affect, and how to add HSTS and a content policy safely.
-
WordPress two-factor authentication and passkeys: a setup guide
Set up WordPress two-factor authentication with any authenticator app, add passkeys, require both by role, and help someone who lost their phone.
Close the open doors today
Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.
Requires WordPress 6.7 or newer and PHP 8.0 or newer.