# Switch from Kadence Security to BetterShield

Bring Kadence Security’s brute force numbers and matching hardening into BetterShield with a preview first, then deactivate the old plugin.

For sites that run Kadence Security now, or ran it before, and are moving to BetterShield.

BetterShield reads the settings Kadence Security left on the site and, after a preview, turns the ones it can match into its own. The old plugin is only read, never changed or switched off.

## What carries over

Only what is switched on in Kadence Security is carried. The first row lands on **Protect › Login & Access**, the rest on **Protect › Hardening**.

| In Kadence Security | In BetterShield |
|---|---|
| Brute force protection, with its maximum attempts per host, check period and lockout period | **Pause sign-in after repeated failures**, with **Failures allowed**, **Counted within (minutes)** and **Pause lasts (minutes)** |
| The file editor turned off | **Disable the dashboard file editor** |
| Directory browsing turned off | **Stop uploads directories listing their contents** |
| PHP in uploads turned off | **Stop PHP running in uploads** |
| XML-RPC turned off in full | **Disable XML-RPC** |

- The numbers are read unless brute force protection was switched off there. They must fit BetterShield’s range: 3 to 100 attempts, and 1 to 1440 minutes for each time.
- The import only turns protections on, never off.

## What does not carry over, and why

The preview lists each one that is switched on there under **Not carried over from**, with the reason.

- **Turning off only XML-RPC pingbacks**: no one-to-one fix, as **Disable XML-RPC** turns all of XML-RPC off. Turn it on yourself if nothing on the site uses XML-RPC.
- **Restricting the REST API for signed-out visitors**: no one-to-one fix. **Block public user listing** covers the list of users; the rest of the REST API stays open.
- **Blocking access to system files**: not carried in this version; review **Hide sensitive files from visitors** instead.
- **A changed sign-in address**: not carried in this version. Set it with **Change the sign-in address** on **Protect › Login & Access**, where it is checked against a working way back in first.
- **Two-factor authentication**: enrollments cannot move between plugins, so each person sets up two-factor again under **Protect › Two-Factor**.
- **Sign-in attempt limits**: held back while the old plugin is active and its brute force protection is on, so two plugins never count the same attempts, or when the numbers fall outside the range.

Anything else is neither read nor listed.

## While Kadence Security is still active

Quick Setup’s **Another security plugin is active** step has a row per shared job, each starting on Kadence Security:

- **Login attempt limits**, only while its brute force protection is on: **Keep** Kadence Security (BetterShield’s own limit goes off) or **Use BetterShield**.
- **Two-factor**: **Keep** Kadence Security, so anyone enrolled there signs in as now, or **Use BetterShield**.
- **Activity log** and **File change monitoring**: **Keep both** or **Use BetterShield only**.
- **Firewall and site scanner**: a statement that BetterShield does not run a firewall or a malware scan.

On **Protect › Login & Access**, **Change the sign-in address** also warns while Kadence Security is active, because both can move or hide the sign-in page.

The Overview’s **Who does which job** card shows the split. Not every overlap is caught, so avoid running sign-in limits or two-factor in both.

## Switch over, step by step

1. Install and activate BetterShield, leaving Kadence Security active. The first audit changes nothing.
2. In Quick Setup, choose who keeps each job and press **Save choices**. Already set up? **Run Quick Setup again** is on **Settings › General**.
3. Go to **BetterShield › Settings › General**. Under **This installation**, **Move settings between sites** lists the plugin under the name your **Plugins** screen shows, as **(active)** or **(not active)**, or as **A security plugin that is no longer installed** if it was deleted but its settings remain.
4. Press **Preview import**. Nothing changes yet. Each fix shows **will be applied**, **already matches**, **cannot work on this server** or **was refused**, with any warning beside it. **Login protection** shows **will change** when your sign-in settings would change.
5. Read the **Not carried over from** list, then press **Make these 4 changes** (the button counts them).
6. Check the result (below), then deactivate Kadence Security on the **Plugins** screen.
7. If the attempt limits were held back, press **Preview import** again. With the old plugin inactive, they carry over.

## What to check after

- Each carried fix shows **On since**, and **Pause sign-in after repeated failures** shows your numbers.
- An audit runs straight after the import. Once the old plugin is deactivated, the finding **Nothing is limiting sign-in attempts** means BetterShield’s limit is off: preview the import again, or switch the limit on.

## Undo the import

No single step reverses the whole import. Each change has its own undo:

- **A fix it turned on**: switch it off on **Protect › Hardening**. Files the fix wrote are put back as they were.
- **Sign-in numbers**: under **Put a settings change back** on **Settings › General**, press **Put it back** on the **Login protection** row. It restores only what the import changed there, and asks you to put any newer change to those settings back first.

Kadence Security itself was never changed.

## Related

- [Install and set up](/docs/install-and-set-up/)
- [Login & Access](/docs/login-and-access/)
- [Hardening](/docs/hardening/)
- [Two-factor and passkeys](/docs/two-factor-and-passkeys/)
- [General settings](/docs/general-settings/)
