# Install BetterShield and run Quick Setup

Install BetterShield, see what activation does, and work through each Quick Setup step with its choices and defaults.

BetterShield installs from WordPress.org. Activating it runs a first audit and opens **Quick Setup**, a short wizard listed under **BetterShield › Quick Setup** until you finish it.

## Requirements

- WordPress 6.7 or newer.
- PHP 8.0 or newer. On older PHP it does not run, and shows a notice instead.

## Install the plugin

1. In your dashboard, go to **Plugins › Add Plugin**.
2. Search for "BetterShield", then install and activate it.

To install by hand, upload the `bettershield` folder to `/wp-content/plugins/` and activate it on the **Plugins** screen.

## What activation does

- **A read-only audit runs**, so the Overview has a score straight away.
- **A single-use recovery link is emailed** to the site's admin address. It gets you back in if you are locked out.
- **Quick Setup opens** the first time you press **Activate** on the Plugins screen. Otherwise (bulk, WP-CLI or another plugin's installer), the Overview shows a **Run the Quick Setup** card.
- **No hardening fix is switched on.** Login attempt limits, a hidden bot check, public form limits, minimum password lengths and email alerts do start now, and each can be switched off.

> **Note:** On multisite, each site gets its own Quick Setup the first time its administrator opens BetterShield.

## Quick Setup, step by step

Up to seven steps; two appear only when they apply. Each step before **Ready** has **Skip**, and a skipped step changes nothing.

### 1. Getting started

**Welcome to BetterShield** asks one question, under **Usage Data**.

- **Get Started** turns usage sharing on: at most once a day, your site address and title, admin email, software versions, language, plugins and theme go to WPDeveloper. Nothing about visitors, users or security events. **What we collect?** lists every field.
- **Skip** sends nothing. You are reminded once, a week later.

Sharing stays off until you press **Get Started**, and can be turned off under **Settings › General**. On multisite, only a super admin is asked.

### 2. Coexistence (only with another security plugin)

**Another security plugin is active** shows one row per job both plugins would do.

| Option | What it does | Why it matters | Default |
|---|---|---|---|
| **Login attempt limits** | **Keep** *[other plugin]* (BetterShield's limit goes off) or **Use BetterShield**. | Two limits lock a person out twice. | Keep the other plugin |
| **Two-factor** | **Keep** *[other plugin]* or **Use BetterShield**. | Nobody is asked for two codes. | Keep the other plugin |
| **Activity log** | **Keep both** or **Use BetterShield only**. | Two logs do no harm. | Keep both |
| **File change monitoring** | **Keep both** or **Use BetterShield only**. | Two watchers do no harm. | Keep both |

Press **Save choices**; nothing changes before that. BetterShield never switches the other plugin off; deactivate it yourself when ready.

### 3. Your site

| Option | What it does | Why it matters | Default |
|---|---|---|---|
| **Who signs in to this site?** | **Just me** or **Me and a team**. | A team is offered required two-factor for administrators next. | **Just me**, unless administrators already need two-factor |
| **Is this site behind Cloudflare or another proxy?** | **No, direct**, **Yes, Cloudflare** or **Yes, another proxy**. | Behind a proxy, one lockout could block every visitor. Add another proxy's addresses in **Protect › Login & Access**. | **No, direct**, or **Yes, Cloudflare** when detected |
| **Security alerts** | **Add another email** adds recipients, up to 5 in total. | Urgent alerts reach somebody. | Admin address |
| **Weekly summary, every Monday** | One email: what changed, was found and was done. | Arrives on quiet weeks too. | On |
| **Instant alerts for high and critical** | Sent as it happens. | Some things cannot wait a week. | On |

Press **Save and continue**.

### 4. Way back in

Titled **Your way back in**.

1. Under **Recovery**, tick **I received the recovery email**, or press **Resend** (a new email stops the old link working).
2. Or press **Download offline recovery codes**. They work without email; keep them off this site.
3. Optional: **Set up two-factor for your account**. Scan the QR code, press **Verify code**, then save your ten backup codes and confirm. **Later** leaves it for **Protect › Two-Factor**.

With **Me and a team**, **Require two-factor for Administrators** unlocks once you tick the email or download the codes. Administrators get 14 days by default; after that the dashboard waits until they set it up, but signing in always works.

### 5. Safe fixes

Five fixes that cannot lock anyone out: **Turn off the file editor**, **Hide the WordPress version**, **Block directory browsing**, **Stop username discovery** and **Add security headers**.

- Each is ticked unless it is **Already on**, and previews its effect. One that warns of a conflict, or that your server cannot support, starts unticked.
- **Stop username discovery** also gives a wrong password and an unknown username the same answer.
- Press **Apply 3 fixes** (the button counts what you ticked), or **Continue** with none ticked.

Changes that could lock people out or are slow to undo, like the login URL or HSTS, stay off until you choose them in **Protect › Hardening**.

### 6. Recommended plugins (optional)

Only for people who can install and activate plugins. Switches start off; **Continue** installs only the WPDeveloper plugins you switch on.

### 7. Ready

**You're set up** shows your **Security grade**, usage sharing, recovery, two-factor, the safe fixes (with **Undo** beside each one BetterShield applied) and where alerts go. **Connect to BetterShield Hub** is optional. Then press **Go to BetterShield Dashboard**.

## Leave, skip or run it again

- **Leave partway:** your answers are kept. The Overview card **Finish the Quick Setup** has **Continue the setup**, which opens where you stopped.
- **Skip to the end:** skipping the step before **Ready** finishes the setup.
- **Run it again:** a finished setup leaves the menu. Go to **Settings › General** and press **Run Quick Setup again**. It opens with your current settings and changes only what you change.

## Where to go next

Read your score on **Overview**, then work through **Findings** and **Protect › Hardening**.

## Related

- [Score and findings](/docs/score-and-findings/)
- [Hardening](/docs/hardening/)
- [Two-factor and passkeys](/docs/two-factor-and-passkeys/)
- [Locked out](/docs/locked-out/)
- [Connect to BetterShield Hub](/docs/connect-to-bettershield-hub/)
- Switching from another security plugin: [From Wordfence](/docs/switch-from-wordfence/), [From All-In-One Security](/docs/switch-from-all-in-one-security/), [From Kadence Security](/docs/switch-from-kadence-security/) or [From Really Simple Security](/docs/switch-from-really-simple-security/)
