BetterShield

Choose BetterShield’s general settings

5 min read

Set the password policy, publish security.txt, choose what leaves the site, ask for your password before protections come off, and plan for uninstall.

BetterShield › Settings › General holds the plugin’s own settings. Email alerts have their own tab: see Email alerts.

What this site checks

Password policy

A minimum for new passwords, checked whenever one is chosen: a reset, a profile change, a new account made from the dashboard, or a store’s account forms. Then press Save policy.

OptionWhat it doesDefault
Ask a minimum standard of new passwordsTurns the policy on.On
Minimum lengthFor most accounts, 6 to 64 characters.8
For admins and editorsFor accounts that can change the site, including any role that can manage options or users. Never lower than Minimum length.12

It also refuses passwords built from the username, email or site name, very common words, or runs such as 12345678.

  • Never applied at sign-in. An older password keeps working, and its owner sees a calm suggestion on their profile.
  • Not checked: application passwords, accounts created by other plugins, imports or WP-CLI, and a password set at a store’s checkout.

Scheduled audits

Shows the next and last daily audit. Run an audit now only reads the site; See the full report opens Findings.

What leaves this site

OptionWhat it doesDefault
Publish a security contactPublishes a security.txt file telling researchers where to report a problem. See below.Off
BetterShield HubConnects this site to the hub. See Connect to BetterShield Hub.Not connected
Your AI agentOpen Agents leads to the assistant switches. See Connect an AI assistant.None
Plain-language explanationsCounts this month’s explanations from your AI provider. Needs WordPress 7.0 and a provider under Settings › Connectors. Up to 20 an hour per account (no limit with Ultra).None
Record what agents do on this siteLogs every ability call from any plugin: name, time, caller, route in and answer. Inputs are kept only as a digest. Needs WordPress 7.1. See Agent activity.On
Share usage dataSends WPDeveloper a short report at most once a day, and once on deactivation: site address and title, admin email, software versions, language, plugins and theme. Nothing about visitors, users or security events. What we collect lists every field. On multisite, only a network administrator can change it.Off
Report a problemPrepare the report describes your setup without your address, email, usernames, IP addresses or keys, ready for Copy the report. Nothing is sent.None

Publish a security contact

  1. Under Where to report a security problem, type the Contact: an email address, or an https address with a form. It saves when you leave the field.
  2. Optionally add a Policy address (optional), an https page.
  3. Turn on Publish a security contact.

The file is built on request at /.well-known/security.txt; nothing is written to disk. The card shows Published, and marked as good until a date a year after you first publish, and Findings flags it 30 days before. If WordPress is installed under a path, the card names where to place a copy yourself.

Confirmations, settings history and uninstall

These are under This installation: what this copy of BetterShield asks before it acts, and what it leaves behind if it goes.

OptionWhat it doesDefault
Run Quick Setup againShown once Quick Setup is finished. It opens with your current settings and changes only what you change.None
Ask for my password before an action that removes a protectionAsks for your password before undoing a hardening fix, importing settings, changing how signing in works, ending sessions or turning a protection off. Adding protection and reading are never asked.Off
Put a settings change backLists recent settings saves, who made each and when. Put it back restores what that save replaced.None

A confirmation lasts fifteen minutes for that sign-in, or until you sign out or reset your password. Safe mode stands the gate down, and passkey-only accounts are never asked.

Move settings between sites

  1. On the first site, press Export settings.
  2. On the other site, press Import a settings file and choose the file. A plan shows what would change.
  3. Press Make these 4 changes (the button counts the changes in the plan).

The file carries hardening, password, sign-in, two-factor, passkey, security.txt, alert and agent settings, plus the password confirmation and deletion choices. Two-factor enrollments, sessions, list authorship, the recovery link and alert recipients stay behind.

Each setting an import changes appears under Put a settings change back; nothing reverses a whole import in one step. If a security plugin BetterShield recognizes left settings here, Preview import brings them over the same way and lists what it could not carry. The other plugin is only read.

Note: The file describes your block lists and sign-in address. Keep it private.

If this plugin is ever deleted

On this card, choose under When this plugin is deleted what happens when BetterShield is deleted (uninstalled):

ChoiceWhat deleting BetterShield then does
Keep everything (default)Keeps the activity log, findings and undo history for a reinstall. Applied fixes stay, including .htaccess rules, with nothing left to take them off. Undo what you do not want first.
Remove this plugin’s recordsTakes off applied fixes, including .htaccess and wp-config.php rules, then removes its records. Quarantined files stay.
Keep a copy of the quarantined files, then remove everythingAs above, after packing the quarantined files into one archive in the quarantine folder under uploads. Collect it over SFTP or your host’s file manager.

What this plugin records, and what it contacts

BetterShield records sign-ins, user and role changes, plugin and theme changes, some settings and its own changes, for 30 days (90 with Ultra). Unless you share usage data, turn on the breached-password check or ask your AI provider for an explanation, it contacts only WordPress.org, sending installed versions. See What BetterShield contacts.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield