Choose BetterShield’s general settings
Set the password policy, publish security.txt, choose what leaves the site, ask for your password before protections come off, and plan for uninstall.
BetterShield › Settings › General holds the plugin’s own settings. Email alerts have their own tab: see Email alerts.
What this site checks
Password policy
A minimum for new passwords, checked whenever one is chosen: a reset, a profile change, a new account made from the dashboard, or a store’s account forms. Then press Save policy.
| Option | What it does | Default |
|---|---|---|
| Ask a minimum standard of new passwords | Turns the policy on. | On |
| Minimum length | For most accounts, 6 to 64 characters. | 8 |
| For admins and editors | For accounts that can change the site, including any role that can manage options or users. Never lower than Minimum length. | 12 |
It also refuses passwords built from the username, email or site name, very common words, or runs such as 12345678.
- Never applied at sign-in. An older password keeps working, and its owner sees a calm suggestion on their profile.
- Not checked: application passwords, accounts created by other plugins, imports or WP-CLI, and a password set at a store’s checkout.
Scheduled audits
Shows the next and last daily audit. Run an audit now only reads the site; See the full report opens Findings.
What leaves this site
| Option | What it does | Default |
|---|---|---|
| Publish a security contact | Publishes a security.txt file telling researchers where to report a problem. See below. | Off |
| BetterShield Hub | Connects this site to the hub. See Connect to BetterShield Hub. | Not connected |
| Your AI agent | Open Agents leads to the assistant switches. See Connect an AI assistant. | None |
| Plain-language explanations | Counts this month’s explanations from your AI provider. Needs WordPress 7.0 and a provider under Settings › Connectors. Up to 20 an hour per account (no limit with Ultra). | None |
| Record what agents do on this site | Logs every ability call from any plugin: name, time, caller, route in and answer. Inputs are kept only as a digest. Needs WordPress 7.1. See Agent activity. | On |
| Share usage data | Sends WPDeveloper a short report at most once a day, and once on deactivation: site address and title, admin email, software versions, language, plugins and theme. Nothing about visitors, users or security events. What we collect lists every field. On multisite, only a network administrator can change it. | Off |
| Report a problem | Prepare the report describes your setup without your address, email, usernames, IP addresses or keys, ready for Copy the report. Nothing is sent. | None |
Publish a security contact
- Under Where to report a security problem, type the Contact: an email address, or an https address with a form. It saves when you leave the field.
- Optionally add a Policy address (optional), an https page.
- Turn on Publish a security contact.
The file is built on request at /.well-known/security.txt; nothing is written to disk. The card shows Published, and marked as good until a date a year after you first publish, and Findings flags it 30 days before. If WordPress is installed under a path, the card names where to place a copy yourself.
Confirmations, settings history and uninstall
These are under This installation: what this copy of BetterShield asks before it acts, and what it leaves behind if it goes.
| Option | What it does | Default |
|---|---|---|
| Run Quick Setup again | Shown once Quick Setup is finished. It opens with your current settings and changes only what you change. | None |
| Ask for my password before an action that removes a protection | Asks for your password before undoing a hardening fix, importing settings, changing how signing in works, ending sessions or turning a protection off. Adding protection and reading are never asked. | Off |
| Put a settings change back | Lists recent settings saves, who made each and when. Put it back restores what that save replaced. | None |
A confirmation lasts fifteen minutes for that sign-in, or until you sign out or reset your password. Safe mode stands the gate down, and passkey-only accounts are never asked.
Move settings between sites
- On the first site, press Export settings.
- On the other site, press Import a settings file and choose the file. A plan shows what would change.
- Press Make these 4 changes (the button counts the changes in the plan).
The file carries hardening, password, sign-in, two-factor, passkey, security.txt, alert and agent settings, plus the password confirmation and deletion choices. Two-factor enrollments, sessions, list authorship, the recovery link and alert recipients stay behind.
Each setting an import changes appears under Put a settings change back; nothing reverses a whole import in one step. If a security plugin BetterShield recognizes left settings here, Preview import brings them over the same way and lists what it could not carry. The other plugin is only read.
Note: The file describes your block lists and sign-in address. Keep it private.
If this plugin is ever deleted
On this card, choose under When this plugin is deleted what happens when BetterShield is deleted (uninstalled):
| Choice | What deleting BetterShield then does |
|---|---|
| Keep everything (default) | Keeps the activity log, findings and undo history for a reinstall. Applied fixes stay, including .htaccess rules, with nothing left to take them off. Undo what you do not want first. |
| Remove this plugin’s records | Takes off applied fixes, including .htaccess and wp-config.php rules, then removes its records. Quarantined files stay. |
| Keep a copy of the quarantined files, then remove everything | As above, after packing the quarantined files into one archive in the quarantine folder under uploads. Collect it over SFTP or your host’s file manager. |
What this plugin records, and what it contacts
BetterShield records sign-ins, user and role changes, plugin and theme changes, some settings and its own changes, for 30 days (90 with Ultra). Unless you share usage data, turn on the breached-password check or ask your AI provider for an explanation, it contacts only WordPress.org, sending installed versions. See What BetterShield contacts.