BetterShield

Switch from Wordfence to BetterShield

4 min read

Bring Wordfence’s sign-in limits, allowed addresses and matching protections into BetterShield with a preview first, then deactivate Wordfence.

For sites that run Wordfence now, or ran it before, and are moving to BetterShield.

BetterShield reads the settings Wordfence left on the site and, after a preview, turns the ones it can match into its own. Wordfence is only read, never changed or switched off.

What carries over

Only what is switched on in Wordfence is carried. The first three land on Protect › Login & Access, the rest on Protect › Hardening.

In WordfenceIn BetterShield
Login security on, with its failures allowed, minutes counted and lockout minutesPause sign-in after repeated failures, with Failures allowed, Counted within (minutes) and Pause lasts (minutes)
Allowlisted IP addressesAlways allowed, each noted “Brought over from another security plugin”
The breached-password checkRefuse passwords found in known breaches
Stopping author scansBlock public user listing
Hiding the WordPress versionStop publishing the WordPress version
Turning off code execution in uploadsStop PHP running in uploads
  • The numbers must fit BetterShield’s range: 3 to 100 failures, and 1 to 1440 minutes for each time.
  • Addresses join Always allowed; nothing there is removed or added twice.
  • The import only turns protections on, never off.

What does not carry over, and why

The preview lists each one that is on in Wordfence under Not carried over from, with the reason.

  • The firewall and its rules: BetterShield does not run a firewall of its own.
  • Rate limiting: no equivalent. Sign-in attempts are limited on Login & Access, and the public forms under Request protection.
  • Country blocking: BetterShield does not block by country.
  • Blocked usernames: Wordfence blocks whoever tries these names. Here a wrong username already counts toward the attempt limit, and a blocked name would stop any account later given it from signing in.
  • Locking out a username that does not exist at once: a wrong username counts toward the limit like any other failure.
  • Two-factor authentication: enrollments cannot move between plugins, so each person sets it up again.
  • Some allowed addresses: only single addresses and CIDR ranges are carried; the rest are named for you to add by hand.
  • Sign-in attempt limits: held back while Wordfence is active and still limits sign-ins, so two plugins never count the same attempts, or when the numbers fall outside the range.

Anything else is neither read nor listed.

While Wordfence is still active

Quick Setup’s Another security plugin is active step has a row per shared job, each starting on Wordfence:

  • Login attempt limits, only while Wordfence’s login security is on: Keep Wordfence (BetterShield’s own limit goes off) or Use BetterShield.
  • Two-factor: Keep Wordfence, so anyone enrolled there signs in as now, or Use BetterShield.
  • File change monitoring: Keep both or Use BetterShield only.
  • Firewall and site scanner: a statement that BetterShield does not run a firewall or a malware scan.

The Overview’s Who does which job card shows the split. Not every overlap is caught, so avoid running sign-in limits or two-factor in both.

Switch over, step by step

  1. Install and activate BetterShield, leaving Wordfence active. The first audit changes nothing.
  2. In Quick Setup, choose who keeps each job and press Save choices. Already set up? Run Quick Setup again is on Settings › General.
  3. Go to BetterShield › Settings › General. Under This installation, Move settings between sites lists Wordfence as (active) or (not active). A deleted plugin whose settings remain shows as A security plugin that is no longer installed.
  4. Press Preview import. Nothing changes yet. Each fix shows will be applied, already matches, cannot work on this server or was refused, with any warning beside it. Login protection shows will change when your sign-in settings would change.
  5. Read the Not carried over from list, then press Make these 4 changes (the button counts them).
  6. Check the result (below), then deactivate Wordfence on the Plugins screen.
  7. If the attempt limits were held back, press Preview import again. With Wordfence inactive they carry over.

What to check after

  • Each carried fix shows On since, Pause sign-in after repeated failures shows your numbers, and Always allowed lists the addresses.
  • An audit runs straight after the import. With Wordfence deactivated, the finding Nothing is limiting sign-in attempts means BetterShield’s limit is off: preview the import again, or switch the limit on.
  • Anyone who used two-factor in Wordfence sets it up again under Protect › Two-Factor.

Undo the import

No single step reverses the whole import. Each change has its own undo:

  • A fix it turned on: switch it off on Protect › Hardening, or on Protect › Login & Access for Refuse passwords found in known breaches. Files the fix wrote are put back as they were.
  • Sign-in numbers and allowed addresses: under Put a settings change back on Settings › General, press Put it back on the Login protection row. It restores only what the import changed there, and asks you to put any newer change to those settings back first.

Wordfence itself was never changed.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield