BetterShield

Run BetterShield on a multisite network

5 min read

Use BetterShield on WordPress multisite: network activation, the Network screen, rules set for every site, and what each site keeps for itself.

On a multisite network, nearly everything BetterShield does belongs to each site. Network administrators also get a BetterShield menu in Network Admin, with Network and Activity.

Network activation

  • Network Activate sets up every site as a single site is set up: a first audit, and a recovery link emailed to that site’s own administration address.
  • A site created later is set up the same way.
  • On a very large network, activation can stop before reaching every site. A site it missed shows Not set up here yet on the Network screen; opening its BetterShield dashboard sets it up.

The Network screen

Every site on this network

One row per site: Site (linking to its BetterShield dashboard), Score with grade, Open findings, Last audit and State. State shows Carried over or Not yet carried over (see below), and No way back in when the site has no working recovery link.

The figures are each site’s own last audit; this screen never runs one. They are kept for up to an hour; Read them again now rereads them. Show more sites loads the next 200.

Set once, for every site

OptionWhat it doesWhy it mattersDefault
Require two-factor across the networkTick roles, set Grace period, in days (0 to 90), press Save.A floor: a site can add roles, not remove the network’s, and the shorter grace period applies.Not set (grace field shows 14)
Passkey-only roles across the networkTick roles and press Save. Those accounts sign in with a passkey, not a password, on every site.Adding a role is refused while any site lacks a working recovery link or printed codes, and on a network of more than 200 sites.Not set
Moving the log to the shared tablesProgress of copying each site’s log, findings, agent record and passkeys into tables the network shares: Not started, In progress, Waiting to retry or Finished, with Sites carried over.Lets the network screens read across sites. Runs hourly, in small batches, and removes nothing.Runs by itself
Recovery link for the networkGenerate recovery link (later Generate a new link) shows one link, once. Opening it pauses enforcement on every site for an hour.A way back in above any one site. A site’s own link opens that site only.None until generated
Rotate the sign-in keysTick I understand every other session on every site will end, then press Rotate the sign-in keys. Everyone else signs in again with their password; you stay signed in.Ends every session on every site. It cannot be put back.None
Recent changes to the networkEach change to the two network rules, with Put back, which changes every site it reached. Shown once there is one.None

The network recovery link works once and lasts 90 days. Using it issues a new one, emailed to the network’s administration address; generating a new one stops the old one.

Changes here need a signed-in browser, and your password again if the main site has Ask for my password before an action that removes a protection on.

What is set for the whole network

  • The two-factor and passkey-only floors above.
  • The network recovery link, and the network-wide pause it starts.
  • The sign-in keys, since one sign-in covers every site.
  • Whether usage data is shared, answered by a super admin.

Everything else is per site: findings, hardening fixes, Login & Access, email alerts, the site’s recovery link and printed codes, AI assistant and BetterShield Hub connections, and settings. A site’s own recovery link and wp bettershield recover pause that site only.

Quick Setup on each site

  • Nobody is redirected on network activation. Each site’s Quick Setup opens the first time its administrator opens BetterShield.
  • Only a super admin is asked about usage data.
  • When the network requires two-factor of administrators, Require two-factor for Administrators shows ticked and locked.
  • Anyone who cannot install and activate plugins, usually a site administrator on a network, skips the recommended plugins step.

Hardening on a network

FixOn a network
Hide sensitive files from visitorsMain site only. It protects every site, as they share one .htaccess.
Stop PHP running in uploadsFrom the main site it covers every site; from another site, that site’s uploads only.
Stop uploads directories listing their contentsPer site: apply it on each site that needs it.
Disable the dashboard file editorChanges nothing for a site administrator: the code editors already belong to network administrators.
Change the sign-in addressThis site only.
Tell browsers to refuse plain HTTPEvery subdomain, set on the main site of a subdomain network, means every site.
Keep low-privilege accounts out of the dashboardNever applies to a super admin.
Strengthen and rotate the sign-in keysNot available on a site’s screen. Rotate from the Network screen.

Activity across sites

BetterShield › Activity in Network Admin lists every site’s activity, each row naming its site, with a Site filter (Every site by default). It has no export and no daily seals. See Activity log.

With Ultra, an Incidents tab beside it lists each site’s open incidents, ten sites at a time.

WP-CLI across sites

wp bettershield activity --sites=all, or a comma-separated list of site IDs, reads the log across sites and adds a site column. Every other command works on the one site WP-CLI runs against.

wp bettershield activity --sites=all --format=csv > network.csv

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield