See your score on the dashboard and in Site Health
BetterShield puts your score on the WordPress dashboard, lists open findings in Site Health, and shows what it keeps about people on the Info tab.
You do not have to open BetterShield to see where the site stands. Two WordPress screens carry its last audit: a widget on the dashboard, and Tools › Site Health. Both read the last audit and never run one; Run audit in BetterShield, or the daily audit, brings them up to date.
The dashboard widget
The BetterShield widget on Dashboard › Home is shown to administrators. It holds:
- The score out of 100, with its grade.
- The open findings: No open findings., or how many there are, with a count for each severity, such as 2 high and 1 low.
- One quiet line: when the last audit ran, and when anything BetterShield controls last changed. For example: “Last audit 2 hours ago. Nothing this plugin controls has changed since” a date. On a new install it says no audit has run yet.
- A safe mode line while safe mode is on: every protection is paused for now, and every setting is kept.
- A muted line while alerts are muted, so a silenced site never looks like a quiet one.
- Open BetterShield, which opens the Overview.
Snoozed findings are still open, so they count here as they do in the score. A finding marked Not applicable does not. See Score and findings.
The widget can be hidden like any other, from Screen Options at the top of the dashboard.
Site Health status
On the Status tab of Tools › Site Health, BetterShield adds its open findings to WordPress’s own tests. Each wears a BetterShield badge, so you can tell them from WordPress’s own security tests.
- One test per open finding, snoozed ones included, under the finding’s own title.
- Critical findings show as critical, with a red badge. Everything else shows as recommended, with a blue badge.
- Each one explains itself: why it matters, what could break if you act on it, when the last audit ran, and See the finding in BetterShield.
- An old audit is flagged. When the last audit is more than two days old, each says the audit is overdue.
- With nothing open, a single test reads BetterShield has no open security findings. It passes while the last audit is under two days old.
A few findings are left out where WordPress’s own Site Health already tests the same thing, so nothing is said twice: The site address is not HTTPS, This PHP version no longer receives security fixes, Debug output is shown to visitors, A WordPress core update is available, Plugins have updates available, Deactivated plugins or themes are still installed, and Anyone can register, and new accounts get more than reader access. Each is left out only when your WordPress version has its own test for it. All of them still appear on BetterShield › Findings and count in the score.
Site Health info
On the Info tab, the section BetterShield: what it keeps about people has one line for each kind of record BetterShield keeps about a person, saying how long it is kept and whether an erasure request removes or keeps it. A last line, How long the activity log is kept, gives the number of days.
Nobody’s data is in it: it describes the records, not what they say. That makes it safe to copy into a support request along with the rest of the Info tab. See Privacy and personal data.