BetterShield

Harden your site with one-click fixes

5 min read

Preview, apply and undo BetterShield’s 16 hardening fixes, trial some on real requests with Monitor first, and see what each one changes.

Ten fixes are on BetterShield › Protect › Hardening, and the six sign-in fixes are under Signing in on Protect › Login & Access. Every fix starts off, and nothing changes until one is turned on.

Preview, apply and undo

  1. Fill in any field the fix has, then press Preview the change. It lists what applying would do, changes nothing, and for XML-RPC and application passwords shows recent use.
  2. Turn the switch on. The row shows On since and Undo never expires.
  3. To undo, turn the switch off. Files the fix wrote are put back as they were.

A note beside the switch warns when another plugin already does the job. A fix your server cannot run shows Not available here.

Applying a Signing in fix first checks your recovery link or printed codes; going ahead anyway is logged. Every apply and undo is logged too, and safe mode pauses every fix.

Monitor first

Monitor first watches real requests without blocking anything. It works for Disable XML-RPC and four Signing in fixes: Change the sign-in address, Refuse application passwords, Keep low-privilege accounts out of the dashboard and Hide the dashboard from visitors.

  1. Choose a New observation window (1 hour, 24 hours or 7 days) and press Start monitoring with the fields above.
  2. It counts requests observed and matched.
  3. When the window ends, press Enforce reviewed settings. It needs a working recovery link or printed codes; undo still works.

Keep low-privilege accounts out of the dashboard also offers Automatic undo for the first 24 hours after 1, 5 or 10 signed-in denials (default Keep undo manual).

Note: A match is not proof of breakage, and no matches is not proof of safety.

The 16 fixes

In screen order, by group. The Signing in group is on Login & Access.

FixWhat it doesWhy it mattersWatch for
What the site reveals
Block public user listingHides usernames from the REST API, author links, the sitemap, embeds and sign-in errors.Guessed usernames cannot be confirmed.A mistyped lost-password address is still told a link is coming.
Stop uploads directories listing their contentsAdds a blank index.php to uploads folders that lack one.Folders cannot be browsed as file lists.Any web server. On a network, apply per site.
Hide sensitive files from visitors.htaccess rules answer 404 for logs, wp-config backups, readme.html, license.txt, .git and .env.A stray wp-config backup can expose the database password.Not on nginx or IIS. On a network, main site only.
Stop publishing the WordPress versionRemoves the version from the generator tag and asset addresses.Scanners use it to choose what to try first.Plugin and theme versions stay.
What can run
Disable XML-RPCAnswers xmlrpc.php with 403. The REST API is untouched.Closes a legacy API and its pingbacks.Jetpack features that need it.
Disable the dashboard file editorRemoves the plugin and theme code editors.No code editing from the dashboard.No change if wp-config.php already disables it, or on a network.
Stop PHP running in uploadsAn uploads .htaccess rule answers 404 for PHP files.An uploaded file can never run as code.Not on nginx or IIS. From a network’s main site, it covers every site.
What browsers are told
Tell browsers to refuse plain HTTPSends HSTS for Five minutes, to prove it works (preselected) or six months, to This domain only (preselected) or every subdomain.Browsers stop using plain HTTP.HTTPS addresses only. See below.
Find out what a content policy would breakSends a report-only content policy and lists what it would block.You see the cost before anything is blocked.Start enforcing this policy unlocks after 7 days with no reports.
Send security response headersAdds four standard headers: content type, framing, referrer and Topics API.Stops content-type guessing and framing by other sites.Headers your server already sends are left alone.
Signing in
Change the sign-in addressMoves sign-in to your New sign-in address. wp-login.php answers 404.Quieter logs, not a stronger door.Note it off the site. The recovery link restores the standard page.
Refuse application passwordsRefuses them for Accounts that can manage this site (preselected) or Every account. Nothing is deleted.They sign in without the second factor.Tools that use them stop working.
Refuse passwords found in known breachesChecks new passwords set by signed-in people against Pwned Passwords, sending only five characters of a hash.A strong-looking password can be on a breach list.Never affects signing in. Registration and reset forms are not checked.
Keep low-privilege accounts out of the dashboardSends the chosen role (preselected: Subscriber) from wp-admin to the front page, except their profile.Subscribers and customers have no need for wp-admin.Never applies to a role that can manage the site.
Hide the dashboard from visitorsSigned-out visitors get a 404 at /wp-admin/ instead of the sign-in form.A moved sign-in address is not given away.admin-ajax.php keeps working.
Strengthen and rotate the sign-in keysMixes a strong secret into the session keys and adds Rotate keys now.Forging a session also needs this secret.Signs other accounts out. On a network, rotate from BetterShield › Network.

What undo cannot reach

  • Strengthen and rotate the sign-in keys: sessions it ended stay ended, and Rotate keys now has no undo.
  • Tell browsers to refuse plain HTTP: a browser that saw the six-month or every-subdomain setting keeps insisting on HTTPS until it expires, whatever you undo. Start with five minutes.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield