# Choose BetterShield’s general settings

Set the password policy, publish security.txt, choose what leaves the site, ask for your password before protections come off, and plan for uninstall.

**BetterShield › Settings › General** holds the plugin's own settings. Email alerts have their own tab: see [Email alerts](/docs/email-alerts/).

## What this site checks

### Password policy

A minimum for new passwords, checked whenever one is chosen: a reset, a profile change, a new account made from the dashboard, or a store's account forms. Then press **Save policy**.

| Option | What it does | Default |
|---|---|---|
| **Ask a minimum standard of new passwords** | Turns the policy on. | On |
| **Minimum length** | For most accounts, 6 to 64 characters. | 8 |
| **For admins and editors** | For accounts that can change the site, including any role that can manage options or users. Never lower than **Minimum length**. | 12 |

It also refuses passwords built from the username, email or site name, very common words, or runs such as 12345678.

- **Never applied at sign-in.** An older password keeps working, and its owner sees a calm suggestion on their profile.
- **Not checked:** application passwords, accounts created by other plugins, imports or WP-CLI, and a password set at a store's checkout.

### Scheduled audits

Shows the next and last daily audit. **Run an audit now** only reads the site; **See the full report** opens Findings.

## What leaves this site

| Option | What it does | Default |
|---|---|---|
| **Publish a security contact** | Publishes a security.txt file telling researchers where to report a problem. See below. | Off |
| **BetterShield Hub** | Connects this site to the hub. See [Connect to BetterShield Hub](/docs/connect-to-bettershield-hub/). | Not connected |
| **Your AI agent** | **Open Agents** leads to the assistant switches. See [Connect an AI assistant](/docs/connect-an-ai-assistant/). | None |
| **Plain-language explanations** | Counts this month's explanations from your AI provider. Needs WordPress 7.0 and a provider under **Settings › Connectors**. Up to 20 an hour per account (no limit with Ultra). | None |
| **Record what agents do on this site** | Logs every ability call from any plugin: name, time, caller, route in and answer. Inputs are kept only as a digest. Needs WordPress 7.1. See [Agent activity](/docs/agent-activity/). | On |
| **Share usage data** | Sends WPDeveloper a short report at most once a day, and once on deactivation: site address and title, admin email, software versions, language, plugins and theme. Nothing about visitors, users or security events. **What we collect** lists every field. On multisite, only a network administrator can change it. | Off |
| **Report a problem** | **Prepare the report** describes your setup without your address, email, usernames, IP addresses or keys, ready for **Copy the report**. Nothing is sent. | None |

### Publish a security contact

1. Under **Where to report a security problem**, type the **Contact**: an email address, or an https address with a form. It saves when you leave the field.
2. Optionally add a **Policy address (optional)**, an https page.
3. Turn on **Publish a security contact**.

The file is built on request at /.well-known/security.txt; nothing is written to disk. The card shows **Published, and marked as good until** a date a year after you first publish, and Findings flags it 30 days before. If WordPress is installed under a path, the card names where to place a copy yourself.

## Confirmations, settings history and uninstall

These are under **This installation**: what this copy of BetterShield asks before it acts, and what it leaves behind if it goes.

| Option | What it does | Default |
|---|---|---|
| **Run Quick Setup again** | Shown once Quick Setup is finished. It opens with your current settings and changes only what you change. | None |
| **Ask for my password before an action that removes a protection** | Asks for your password before undoing a hardening fix, importing settings, changing how signing in works, ending sessions or turning a protection off. Adding protection and reading are never asked. | Off |
| **Put a settings change back** | Lists recent settings saves, who made each and when. **Put it back** restores what that save replaced. | None |

A confirmation lasts fifteen minutes for that sign-in, or until you sign out or reset your password. Safe mode stands the gate down, and passkey-only accounts are never asked.

### Move settings between sites

1. On the first site, press **Export settings**.
2. On the other site, press **Import a settings file** and choose the file. A plan shows what would change.
3. Press **Make these 4 changes** (the button counts the changes in the plan).

The file carries hardening, password, sign-in, two-factor, passkey, security.txt, alert and agent settings, plus the password confirmation and deletion choices. Two-factor enrollments, sessions, list authorship, the recovery link and alert recipients stay behind.

Each setting an import changes appears under **Put a settings change back**; nothing reverses a whole import in one step. If a security plugin BetterShield recognizes left settings here, **Preview import** brings them over the same way and lists what it could not carry. The other plugin is only read.

> **Note:** The file describes your block lists and sign-in address. Keep it private.

### If this plugin is ever deleted

On this card, choose under **When this plugin is deleted** what happens when BetterShield is deleted (uninstalled):

| Choice | What deleting BetterShield then does |
|---|---|
| **Keep everything** (default) | Keeps the activity log, findings and undo history for a reinstall. Applied fixes stay, including .htaccess rules, with nothing left to take them off. Undo what you do not want first. |
| **Remove this plugin's records** | Takes off applied fixes, including .htaccess and wp-config.php rules, then removes its records. Quarantined files stay. |
| **Keep a copy of the quarantined files, then remove everything** | As above, after packing the quarantined files into one archive in the quarantine folder under uploads. Collect it over SFTP or your host's file manager. |

## What this plugin records, and what it contacts

BetterShield records sign-ins, user and role changes, plugin and theme changes, some settings and its own changes, for 30 days (90 with Ultra). Unless you share usage data, turn on the breached-password check or ask your AI provider for an explanation, it contacts only WordPress.org, sending installed versions. See [What BetterShield contacts](/docs/what-bettershield-contacts/).

## Related

- [Login & Access](/docs/login-and-access/)
- [Connect to BetterShield Hub](/docs/connect-to-bettershield-hub/)
- [WP-CLI commands](/docs/wp-cli-commands/)
- [Privacy and personal data](/docs/privacy-and-personal-data/)
