# Switch from Really Simple Security to BetterShield

Bring Really Simple Security’s login attempt numbers and hardening into BetterShield with a preview first, then deactivate the old plugin.

For sites that run Really Simple Security now, or ran it before, and are moving to BetterShield.

BetterShield reads the settings Really Simple Security left on the site and, after a preview, turns the ones it can match into its own. The old plugin is only read, never changed or switched off.

## What carries over

Only what is switched on in Really Simple Security is carried. The first row lands on **Protect › Login & Access**, the rest on **Protect › Hardening**.

| In Really Simple Security | In BetterShield |
|---|---|
| Limited login attempts on, with the number of attempts, the period they are counted over and the lockout duration | **Pause sign-in after repeated failures**, with **Failures allowed**, **Counted within (minutes)** and **Pause lasts (minutes)** |
| Disabling file editing | **Disable the dashboard file editor** |
| Disabling XML-RPC | **Disable XML-RPC** |
| Disabling user enumeration | **Block public user listing** |
| Disabling directory indexing | **Stop uploads directories listing their contents** |
| Hiding the WordPress version | **Stop publishing the WordPress version** |
| Blocking code execution in uploads | **Stop PHP running in uploads** |

- The numbers are read as minutes and must fit BetterShield’s range: 3 to 100 attempts, and 1 to 1440 minutes for each time.
- The import only turns protections on, never off.

## What does not carry over, and why

One setting can be held back, and the preview lists it under **Not carried over from**, with the reason:

- **Sign-in attempt limits**: held back while Really Simple Security is active and still limits login attempts, so two plugins never count the same attempts. Also listed when the numbers fall outside the range, with the numbers it found.

Anything else is neither read nor listed. Two-factor enrollments never travel in an import, so anyone who used two-factor in the old plugin sets it up again under **Protect › Two-Factor**.

## While Really Simple Security is still active

Quick Setup’s **Another security plugin is active** step has a row per shared job, each starting on Really Simple Security. Which rows appear depends on the edition that is active:

- **Two-factor**, always: **Keep** Really Simple Security, so anyone enrolled there signs in as now, or **Use BetterShield**.
- **Login attempt limits**, only while its own login attempt limit is on: **Keep** Really Simple Security (BetterShield’s own limit goes off) or **Use BetterShield**.
- **Firewall and site scanner**: a statement that BetterShield does not run a firewall or a malware scan.

The Overview’s **Who does which job** card shows the split. Not every overlap is caught, so avoid running login attempt limits or two-factor in both.

## Switch over, step by step

1. Install and activate BetterShield, leaving Really Simple Security active. The first audit changes nothing.
2. In Quick Setup, choose who keeps each job and press **Save choices**. Already set up? **Run Quick Setup again** is on **Settings › General**.
3. Go to **BetterShield › Settings › General**. Under **This installation**, **Move settings between sites** lists the plugin under the name your **Plugins** screen shows, as **(active)** or **(not active)**, or as **A security plugin that is no longer installed** if it was deleted but its settings remain.
4. Press **Preview import**. Nothing changes yet. Each fix shows **will be applied**, **already matches**, **cannot work on this server** or **was refused**, with any warning beside it. **Login protection** shows **will change** when your sign-in settings would change.
5. Read the **Not carried over from** list, if there is one, then press **Make these 4 changes** (the button counts them).
6. Check the result (below), then deactivate Really Simple Security on the **Plugins** screen.
7. If the attempt limits were held back, press **Preview import** again. With the old plugin inactive, they carry over.

> **Note:** If the button reads **Nothing here can be carried over**, nothing in the table is switched on there that BetterShield can carry now.

## What to check after

- Each carried fix shows **On since**, and **Pause sign-in after repeated failures** shows your numbers.
- An audit runs straight after the import. Once the old plugin is deactivated, the finding **Nothing is limiting sign-in attempts** means BetterShield’s limit is off: preview the import again, or switch the limit on.
- A fix the preview marked **cannot work on this server** was not applied. **Protect › Hardening** shows it as **Not available here**, with the reason.

## Undo the import

No single step reverses the whole import. Each change has its own undo:

- **A fix it turned on**: switch it off on **Protect › Hardening**. Files the fix wrote are put back as they were.
- **Sign-in numbers**: under **Put a settings change back** on **Settings › General**, press **Put it back** on the **Login protection** row. It restores only what the import changed there, and asks you to put any newer change to those settings back first.

Really Simple Security itself was never changed.

## Related

- [Install and set up](/docs/install-and-set-up/)
- [Login & Access](/docs/login-and-access/)
- [Hardening](/docs/hardening/)
- [Two-factor and passkeys](/docs/two-factor-and-passkeys/)
- [General settings](/docs/general-settings/)
