BetterShield

Connect a site to BetterShield Hub

4 min read

Connect a WordPress site to BetterShield Hub: choose read-only or read-and-fix, approve it on the site’s own consent page, and disconnect at any time.

BetterShield Hub is a free, optional dashboard for people who look after several sites. You connect each site from its own BetterShield › Hub screen (listed as BetterShield Hub under Agents in the plugin’s sidebar). The same card is on Settings › General under What leaves this site, and at the end of Quick Setup as Connect to BetterShield Hub.

Before you start

  • The site runs BetterShield 1.1.0 or newer.
  • You are signed in as an administrator who can manage BetterShield. The same account starts the connection and approves it.
  • Everything in BetterShield works without the hub. Nothing on the site waits on it.

Connect a site

  1. Go to BetterShield › Hub.
  2. Under What the hub may do, choose Read this site and apply fixes that can be undone (the default) or Read this site only.
  3. Press Connect to BetterShield Hub.
  4. Your browser opens BetterShield Hub, which brings you back to this site’s own consent page. Finish within 15 minutes, or start again from step 1.
  5. Check the consent page and press Connect. Not now cancels.

Before your browser leaves, BetterShield turns on what the connection needs under Agents › Connect, if it is off: Let an assistant connect to this site and Let my agent read security information, plus Let agents act: changes that can be undone right away, anything heavier once you agree for read-and-fix. It never turns any of them off.

The page is titled Connect an assistant and lists the Site, who you are Signed in as, and where it Sends you back to, which should be the hub’s address.

  • Allow it to change this site appears when you chose read-and-fix, and is ticked by default. Untick it to connect read-only.
  • If Ask for my password before an action that removes a protection is on under Settings › General, the page asks for your password to allow changes. Unticking the box connects for reading without it.
  • The page refuses a hub connection that was not started from this site’s dashboard by the account approving it.

What the hub can see and do

  • Read this site only: the hub sees the score, findings and a few security views, such as administrators by display name and role. It changes nothing.
  • Read this site and apply fixes that can be undone: the hub can also apply and undo fixes, and only ones that can be undone.

Either way:

  • The score, findings and fixes are still worked out on the site. The hub shows what the site reports.
  • The connection runs as the account that approved it, and every change the hub makes is recorded in the site’s activity log.
  • Changes to how people sign in, and taking a protection off, wait for a person to agree each time.
  • The site never contacts the hub. The hub contacts the site, and checks every few minutes that its front page answers.

If you later turn off Let agents act: changes that can be undone right away, anything heavier once you agree under Agents › Connect, the hub can still read but changes nothing. See BetterShield Hub for what the hub does with this across your sites.

Hub address

The card shows Hub address, https://hub.bettershield.ai by default.

OptionWhat it doesDefault
ChangeOpens the Hub address field. Enter an https address with no query, fragment or user name, then press Save address. Leave it empty for the default.Not shown while connected (“disconnect to change it”)
BETTERSHIELD_HUB_URL in wp-config.phpPins the address, for hosts that manage many sites. The card then shows “(set in wp-config.php)” and the address cannot be changed on screen.Not set

To move a connected site to another hub address, disconnect, change the address, then connect again.

If the card says the hub is refused

A connected site can still refuse the hub, and the card names why:

  • The site is marked as a staging copy. Undo that answer on the Overview.
  • Let an assistant connect to this site is off under Agents › Connect.
  • Let my agent read security information is off under Agents › Connect.

The connection is kept, and the hub is let in again once every reason is undone.

Disconnect

  1. Go to BetterShield › Hub.
  2. Press Disconnect. Every hub connection on this site ends at once.

The connection is also listed under Agents › Connect in Connected apps, where Revoke ends it too.

Note: Removing a site inside the hub does not end the connection. Only Disconnect (or Revoke) on the site does.

Disconnecting leaves the Agents › Connect switches as they are. Turn them off there if no other assistant uses them.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield