Get back in when you’re locked out
Locked out of WordPress by BetterShield? Use your recovery link or a printed code to pause its protections for an hour and sign in again.
If BetterShield is stopping you from signing in, your recovery link or a printed recovery code pauses its protections for one hour, with nothing deactivated and no setting changed. You manage both under BetterShield › Protect › Recovery.
Use your recovery link
The recovery link is a private address for your site. BetterShield emailed it to the site’s administration email address when you activated it (and again if you resent it from Quick Setup), with the subject “[your site] Your BetterShield recovery link”. If a link has been used since, the newest one arrived in an email titled “Your BetterShield recovery link was used on [your site]”. A link you generated on the Recovery screen was shown there, not emailed.
- Open the newest link in your browser. Opening it changes nothing yet.
- On Pause protection and get back in?, press Pause protection and continue.
- The Safe mode is on page says when the pause ends. Under Save your next recovery link it shows a new link: copy it somewhere safe now. A copy is also emailed to the administration address.
- Press Go to sign-in and sign in with your username and password.
Each link works once: using it spends it and issues the next one straight away. A link also stops working 90 days after it was issued, or as soon as a newer one is generated. A spent, replaced or expired link shows “This recovery link or code is not valid.”
For that hour, BetterShield stops enforcing lockouts, the blocklist, a moved sign-in address, session limits and its two-factor step, so the standard sign-in page works again. Safe mode ends on its own; to end it sooner, press End safe mode now on the Overview.
Use a printed recovery code
Printed codes work without email. Each sheet lists eight codes and the address to use them at.
- Open the address printed on the sheet with one code added to the end, typed as printed.
- Press Pause protection and continue. Only that code is spent; your other codes keep working.
- The Safe mode is on page says how many codes you have left. Press Go to sign-in.
A code does not issue a new link. When your codes run low, issue a new set from the Recovery screen.
If you have neither
- Locked out after wrong passwords. A sign-in lockout ends on its own (15 minutes by default, longer if it keeps happening within a day). The account’s email address also receives “[site name] Sign-in temporarily locked” with an unlock link: open it and press Clear the lockout.
- Another administrator can still sign in. They can generate a new recovery link for you under Protect › Recovery, or fix whatever is blocking you.
- You or your host can run WP-CLI.
wp bettershield recoverturns safe mode on for one hour and needs no user account. Add--hours=4for longer (1 to 24 hours) or--new-linkto print a fresh recovery link (the old one stops working).wp bettershield recover --endends safe mode early.
Lost your two-factor device
- Use a backup code. Setting up two-factor gave you ten backup codes. On the code screen, type one in place of the app code. Each works once.
- No backup codes left? An administrator can open your account under Users, find Two-factor sign-in and press Turn off two-factor for this account. You then sign in with your password and set two-factor up again.
- The only administrator? Your recovery link or a printed code gets you into the dashboard, because the two-factor step is not asked while safe mode lasts.
Before you need it
On BetterShield › Protect › Recovery, in the order the screen shows them:
| Option | What it does | Why it matters | Default |
|---|---|---|---|
| Generate a new link (Generate recovery link if none exists) | Makes a new recovery link, good for 90 days, and shows it once, with Copy link. The old link stops working. A link made here is not emailed. | Keep it outside the site, such as in a password manager. In a link’s last 14 days, Findings shows “The recovery link is close to expiring”. | One link, emailed at activation |
| Issue recovery codes | Shows eight single-use codes once, with Print and Copy all. Issue a new set replaces any unused codes. | Your way back on the day email is broken. | None until you issue them |
| Check readiness now | Checks the link, your unused codes, an administrator email address and the email path. Never uses a link or code. | Shows a broken way back early. | Runs daily on its own |
| Send a weekly recovery email check | Sends a test email to your alert recipients at most once a week. | Shows whether mail actually leaves the site. | Off |
| Lock the site down | Signs out every other dashboard session, refuses sign-ins from accounts that cannot manage the site, turns off XML-RPC and application passwords, and stops registrations, installs and updates. Never expires; Lift the lockdown ends it. The front end and a WooCommerce checkout keep working. | For an emergency. Your recovery link pauses it too. | Off |
Before a change to how people sign in, such as moving the sign-in address or requiring two-factor for a role, BetterShield checks that you have a working recovery link or an unused printed code.
Note: On multisite, the network’s BetterShield › Network screen has a Recovery link for the network, which pauses enforcement on every site for an hour.