Choose who gets security alerts
Choose who gets BetterShield’s alert emails, set the weekly summary day, pause routine alerts for maintenance, mute, and test delivery.
BetterShield emails a weekly summary, and an alert straight away for anything rated high or critical. Set both under BetterShield › Settings › Email alerts; Quick Setup asks the same questions in its Your site step.
When alerts are sent, and to whom
| Option | What it does | Why it matters | Default |
|---|---|---|---|
| Mute all alerts | Stops every alert and the weekly summary. The switches below read off while muted and come back as you left them. | For a noisy spell. The Overview, the dashboard widget and the activity log show it. | Off |
| Planned maintenance | Pick a Duration (30 minutes, 1 hour, 2 hours or 4 hours) and press Start maintenance. Routine instant alerts are held, and one summary goes out when it ends (if instant alerts are on). End maintenance ends it early. | Planned work does not flood the inbox. Critical events, decoy hits, lockdowns and changes to protections still go out, and every protection stays on. | Not running, 2 hours preselected |
| Where alerts go | Type an address under Add an address and press Add, up to 5. Remove takes one off. Addresses need not be accounts on the site. | Alerts reach someone who will act. | The site’s administration email, while none is named |
| Send a test alert | Sends one real “Alert delivery test” by the path every alert takes, and says whether WordPress accepted it. One every few minutes. | A broken mail setup shows up here, not as silence. | None |
Maintenance holds routine alerts such as a new administrator, a role change, or a plugin switched on with nobody signed in. Starting it is itself alerted.
What muting does not stop: the site is still watched and logged, and findings still open and close. Mail about a person’s own account still reaches them: the link that clears a sign-in lockout, the new-network sign-in notice (where it is on), and a replacement recovery link. Alerts that queue while muted are dropped, not sent later.
Telling the Overview that a moved site is a staging copy also turns the mute on. With Ultra, muting also stops alert destinations under Ultra › Alert channels.
Weekly summary and instant alerts
These are under What is worth sending.
| Option | What it does | Why it matters | Default |
|---|---|---|---|
| Send a weekly summary | One email covering everything since the last summary. | It arrives on quiet weeks too. | On |
| Day | Sunday to Saturday, in the site’s time zone. | Monday | |
| Send one now | Sends the real summary now. The next covers from this moment and still arrives on your day. | None | |
| Email me about high and critical events as they happen | Emails each high or critical event; everything else waits for the summary. | Some things cannot wait a week. | On |
| Whether these are worth sending | Alerts sent over the log’s retention (30 days, or 90 with Ultra), and how many were marked unhelpful with That alert was not worth sending on a finding opened from an alert. | None |
What is sent straight away
Events the activity log tags High or Critical. The main ones:
- Critical: a core, plugin or other watched file altered, or new code where nothing published it; the decoy credential used or decoy URL requested; the site locked down.
- Accounts: an administrator or editor account created, deleted, or its email changed; on such an account, an application password created, a passkey added or removed, or two-factor turned off; a role that can manage settings or users given or taken away; a change to what a role may do; email, password and application password all changed within an hour.
- Site settings: site or home address, administration email, open registration or default role changed; a plugin or theme switched on with nobody signed in.
- Protections: two-factor or login protection loosened; a site’s passkey-only roles changed; the decoy URL or credential turned off; a protection found missing on a live page; safe mode started; the lockdown lifted; maintenance started.
- Other: a passkey refused; an AI assistant connected; an agent changing something on its own; a quarantined file deleted; an update that did not match its published copy.
The first alert goes at once; anything in the next five minutes joins one follow-up. Nothing is sent while a visitor waits on a page; it goes with the next dashboard page, WP-CLI run or hourly task. A refused send is retried hourly, three times, then logged as “Alert could not be delivered”.
What an alert contains
Emails are plain text, sent through WordPress to the addresses above only, with the site name in brackets at the start of the subject.
- An instant alert names the event (or how many), lists each with its time in UTC, asks you to check each was you or someone you know, and links to the activity log.
- The weekly summary gives the dates covered, score, grade, open findings, what opened (with links) and resolved, activity by area, and the highest-rated open finding to look at next.
- Every email ends with a link to this screen.
The screen’s What an alert never contains card states what no switch changes: no prompt to upgrade, no price and no link to buy anything; no exaggeration; and nothing leaves the site but the message itself.
Turning alerts down
Muting, starting maintenance, switching a message off or removing an address needs a signed-in browser, and your password again if Ask for my password before an action that removes a protection is on (Settings › General). Each save is logged as “Alert settings changed”, and Put a settings change back on Settings › General can restore it.
The weekly recovery email check
Send a weekly recovery email check on Protect › Recovery sends a test to these same addresses, at most weekly. Muting, or having no address, stops it, and the readiness check says so. See Locked out.