Locked out of WordPress? How to get back in without FTP
Getting locked out of WordPress usually happens at an inconvenient moment: a few mistyped passwords, a sign-in address you moved months ago, or a new phone without your authenticator app. The usual way out involves FTP, a database tool or a support ticket with your host.
With BetterShield on the site, you rarely need any of those. A single-use recovery link is emailed to the site’s admin address when you activate it, printed codes work when email does not, and each kind of lockout has its own way out, from a browser or a terminal.
One thing to know first: these tools pause BetterShield’s own protections for a while. They do not change your password, and you still sign in with your own username and password.
Quick summary
- A lockout after wrong passwords ends on its own, and when it names a real account, that account’s email gets an unlock link.
- Your recovery link, or one printed recovery code, turns on safe mode for one hour, so the standard sign-in page works again.
- A lost two-factor phone is covered by your ten backup codes, or by an administrator turning two-factor off for you.
- With no link and no codes, another administrator or
wp bettershield recovergets you back in. - Set it all up in advance on BetterShield › Protect › Recovery.
Common reasons you get locked out of WordPress
Most lockouts come from ordinary, honest slips:
- Too many wrong passwords. A password manager fills in an old password, or you try a few from memory, and sign-in from your connection pauses.
- A moved sign-in address you have forgotten. Without the bookmark, the standard sign-in page answers 404.
- A lost two-factor device. A new, lost or reset phone takes your authenticator app with it.
- A sign-in rule that is too strict. A blocked range that includes your own network, or a passkey-only rule and a missing passkey.
- Email that never arrives. Reset and unlock messages never reach you, so you can’t log in to WordPress the usual way.
The recovery link and safe mode
The recovery link is a private address for your site, emailed at activation with the subject “[your site] Your BetterShield recovery link”. If a link has been used since, the newest one is in an email titled “Your BetterShield recovery link was used on [your site]”.
- Open the newest link in your browser. Opening it changes nothing yet.
- On Pause protection and get back in?, press Pause protection and continue.
- The Safe mode is on page says when the pause ends. Under Save your next recovery link, copy the new link somewhere safe.
- Press Go to sign-in and sign in with your username and password.
For that hour, BetterShield stops enforcing lockouts, the blocklist, a moved sign-in address, session limits and its two-factor step. Nothing is deactivated and no setting changes. Safe mode ends on its own, or sooner with End safe mode now on the Overview.
Each link works once, and using it issues the next one straight away. A link also stops working 90 days after it was issued, or as soon as a newer one is generated.
Printed recovery codes, for when email is the problem
Printed codes never touch email. Each sheet lists eight single-use codes and the address to use them at.
- Open the address printed on the sheet with one code added to the end, typed as printed.
- Press Pause protection and continue. Only that code is spent.
- The Safe mode is on page says how many codes are left. Press Go to sign-in.
When your codes run low, issue a new set from the Recovery screen.
Match the lockout to its way back in
Too many wrong passwords
When your WordPress login is locked out after wrong passwords, BetterShield has paused sign-in from that connection, not your account. The pause ends on its own: 15 minutes by default, longer if it keeps happening within a day.
If the attempts named a real account, its email address receives “[site name] Sign-in temporarily locked” with an unlock link. Open it and press Clear the lockout. Another administrator can also press Release now under Lockouts on Protect › Login & Access.
A moved sign-in address
Use your recovery link or a printed code. While safe mode lasts, Go to sign-in takes you to the standard page. Once you are in, turn Change the sign-in address off under Signing in on Protect › Login & Access, or keep it and note the address somewhere off the site. See Hardening.
A lost two-factor device
- Use a backup code. On the Authentication code screen, type one of your ten backup codes in place of the app code. Once you are in, another unused code under Turn off on Protect › Two-Factor turns it off, so you can set it up again on your new phone.
- No backup codes left? An administrator opens your account under Users, finds Two-factor sign-in and presses Turn off two-factor for this account.
- The only administrator? Your recovery link or a printed code gets you into the dashboard, because the two-factor step is not asked while safe mode lasts.
More in Two-factor and passkeys.
A sign-in rule that is too strict
Use your recovery link or a printed code, then fix the rule while you are in. A blocked range or user agent lives under Never allowed to sign in on Login & Access. On a passkey-only account, the recovery link or a printed code brings password sign-in back.
Email that never arrives
Printed codes are the answer, because they never depend on email. After you use a link, the Safe mode is on page shows the next one on screen, so you are never waiting on an inbox for it.
When you have neither a link nor a code
- Another administrator can still sign in. They can generate a new recovery link for you under Protect › Recovery, or fix whatever is blocking you.
- You or your host can run WP-CLI.
wp bettershield recoverturns safe mode on for one hour and needs no user account. Add--hours=4for longer (1 to 24 hours), or--new-linkto print a fresh recovery link.wp bettershield recover --endends safe mode early.
WP-CLI commands lists every option.
Before you need it
Set up your way back in while you can still sign in. On BetterShield › Protect › Recovery:
- Generate a new link makes a fresh link and shows it once, with Copy link. It is not emailed, and the old link stops working. Keep it outside the site, such as in a password manager.
- A link works for 90 days. In its last 14 days, Findings shows “The recovery link is close to expiring”.
- Issue recovery codes shows eight codes once, with Print and Copy all.
- Check readiness now checks the link, your unused codes, an administrator email address and the email path, without using a link or code. It also runs daily on its own.
- Send a weekly recovery email check sends a test email to your alert recipients at most once a week. It is off by default. Mail accepted for sending is not proof it arrived, so look for it in your inbox.
Quick Setup covers the same ground in its Your way back in step. See Install and set up.
Why BetterShield checks your way back in first
The moment you tighten sign-in is the moment a small slip could keep you out. So before a Signing in fix such as Change the sign-in address, or before a role is added to Require two-factor of a role, BetterShield checks that you have a way back.
The check passes when there is a working recovery link or an unused printed code, and the recovery options were checked within the last day. If it does not pass, Check the way back in first says why and offers Check now or Open Recovery. Go ahead anyway is there too, and is recorded in the activity log. From WP-CLI, wp bettershield harden stops with the same reason until you add --force.
Passkey-only sign-in is stricter: adding a role is refused without a working recovery link or printed codes. Undoing a fix is never held up.
Common mistakes
- Keeping the link or codes only on the site. A copy inside the site does not help when the site is what you cannot reach.
- Opening an old link. Each link works once. Use the newest one.
- Guessing at two-factor codes. After ten wrong codes in an hour, that account’s codes are not checked for a while, and wrong codes count toward a lockout. Use a backup code instead.
- Leaving the cause in place. Safe mode ends after the hour, so fix what kept you out while you are in.
Frequently asked questions
Does the recovery link deactivate BetterShield?
No. It pauses BetterShield’s protections for one hour, with nothing deactivated and no setting changed. Safe mode then ends on its own.
Can I reset a WordPress login without FTP?
Yes, for anything BetterShield enforces: the recovery link, a printed code or wp bettershield recover brings back the standard sign-in page. These tools do not change passwords, though. A forgotten password goes through WordPress’s own Lost your password? link.
Can I get back in if my site cannot send email?
Yes. Printed recovery codes work without email, and wp bettershield recover needs neither email nor a user account.
Is lockout recovery part of the free plugin?
Yes. The recovery link, printed codes, lockout emails, two-factor backup codes and the WP-CLI commands are all in the free BetterShield plugin on WordPress.org. No account or sign-up is needed.
Conclusion
Most WordPress lockouts are small, honest mistakes, and with BetterShield none of them needs FTP or a call to your host. A lockout ends on its own or with its email, a lost phone has its backup codes, and the recovery link or a printed code covers the rest.
Spend a few minutes on Protect › Recovery today: save a fresh link, print your codes and press Check readiness now. The full reference is the Locked out guide, and Support is there if you get stuck.