# Harden your site with one-click fixes

Preview, apply and undo BetterShield’s 16 hardening fixes, trial some on real requests with Monitor first, and see what each one changes.

Ten fixes are on **BetterShield › Protect › Hardening**, and the six sign-in fixes are under **Signing in** on **Protect › Login & Access**. Every fix starts off, and nothing changes until one is turned on.

## Preview, apply and undo

1. Fill in any field the fix has, then press **Preview the change**. It lists what applying would do, changes nothing, and for XML-RPC and application passwords shows recent use.
2. Turn the switch on. The row shows **On since** and **Undo never expires**.
3. To undo, turn the switch off. Files the fix wrote are put back as they were.

A note beside the switch warns when another plugin already does the job. A fix your server cannot run shows **Not available here**.

Applying a **Signing in** fix first checks your recovery link or printed codes; going ahead anyway is logged. Every apply and undo is logged too, and safe mode pauses every fix.

## Monitor first

**Monitor first** watches real requests without blocking anything. It works for **Disable XML-RPC** and four **Signing in** fixes: **Change the sign-in address**, **Refuse application passwords**, **Keep low-privilege accounts out of the dashboard** and **Hide the dashboard from visitors**.

1. Choose a **New observation window** (**1 hour**, **24 hours** or **7 days**) and press **Start monitoring with the fields above**.
2. It counts requests observed and matched.
3. When the window ends, press **Enforce reviewed settings**. It needs a working recovery link or printed codes; undo still works.

**Keep low-privilege accounts out of the dashboard** also offers **Automatic undo for the first 24 hours** after 1, 5 or 10 signed-in denials (default **Keep undo manual**).

> **Note:** A match is not proof of breakage, and no matches is not proof of safety.

## The 16 fixes

In screen order, by group. The **Signing in** group is on Login & Access.

| Fix | What it does | Why it matters | Watch for |
|---|---|---|---|
| *What the site reveals* | | | |
| **Block public user listing** | Hides usernames from the REST API, author links, the sitemap, embeds and sign-in errors. | Guessed usernames cannot be confirmed. | A mistyped lost-password address is still told a link is coming. |
| **Stop uploads directories listing their contents** | Adds a blank index.php to uploads folders that lack one. | Folders cannot be browsed as file lists. | Any web server. On a network, apply per site. |
| **Hide sensitive files from visitors** | .htaccess rules answer 404 for logs, wp-config backups, readme.html, license.txt, .git and .env. | A stray wp-config backup can expose the database password. | Not on nginx or IIS. On a network, main site only. |
| **Stop publishing the WordPress version** | Removes the version from the generator tag and asset addresses. | Scanners use it to choose what to try first. | Plugin and theme versions stay. |
| *What can run* | | | |
| **Disable XML-RPC** | Answers xmlrpc.php with 403. The REST API is untouched. | Closes a legacy API and its pingbacks. | Jetpack features that need it. |
| **Disable the dashboard file editor** | Removes the plugin and theme code editors. | No code editing from the dashboard. | No change if wp-config.php already disables it, or on a network. |
| **Stop PHP running in uploads** | An uploads .htaccess rule answers 404 for PHP files. | An uploaded file can never run as code. | Not on nginx or IIS. From a network's main site, it covers every site. |
| *What browsers are told* | | | |
| **Tell browsers to refuse plain HTTP** | Sends HSTS for **Five minutes, to prove it works** (preselected) or six months, to **This domain only** (preselected) or every subdomain. | Browsers stop using plain HTTP. | HTTPS addresses only. See below. |
| **Find out what a content policy would break** | Sends a report-only content policy and lists what it would block. | You see the cost before anything is blocked. | **Start enforcing this policy** unlocks after 7 days with no reports. |
| **Send security response headers** | Adds four standard headers: content type, framing, referrer and Topics API. | Stops content-type guessing and framing by other sites. | Headers your server already sends are left alone. |
| *Signing in* | | | |
| **Change the sign-in address** | Moves sign-in to your **New sign-in address**. wp-login.php answers 404. | Quieter logs, not a stronger door. | Note it off the site. The recovery link restores the standard page. |
| **Refuse application passwords** | Refuses them for **Accounts that can manage this site** (preselected) or **Every account**. Nothing is deleted. | They sign in without the second factor. | Tools that use them stop working. |
| **Refuse passwords found in known breaches** | Checks new passwords set by signed-in people against Pwned Passwords, sending only five characters of a hash. | A strong-looking password can be on a breach list. | Never affects signing in. Registration and reset forms are not checked. |
| **Keep low-privilege accounts out of the dashboard** | Sends the chosen role (preselected: Subscriber) from wp-admin to the front page, except their profile. | Subscribers and customers have no need for wp-admin. | Never applies to a role that can manage the site. |
| **Hide the dashboard from visitors** | Signed-out visitors get a 404 at /wp-admin/ instead of the sign-in form. | A moved sign-in address is not given away. | admin-ajax.php keeps working. |
| **Strengthen and rotate the sign-in keys** | Mixes a strong secret into the session keys and adds **Rotate keys now**. | Forging a session also needs this secret. | Signs other accounts out. On a network, rotate from **BetterShield › Network**. |

## What undo cannot reach

- **Strengthen and rotate the sign-in keys**: sessions it ended stay ended, and **Rotate keys now** has no undo.
- **Tell browsers to refuse plain HTTP**: a browser that saw the six-month or every-subdomain setting keeps insisting on HTTPS until it expires, whatever you undo. Start with five minutes.

## Related

- [Score and findings](/docs/score-and-findings/)
- [Two-factor and passkeys](/docs/two-factor-and-passkeys/)
- [Locked out](/docs/locked-out/)
