For people who look after other people’s sites.
BetterShield is complete on its own: the whole diagnosis, every finding, every one-click fix, and an undo for each of them. Ultra unlocks none of that. It adds speed, automation and scale for the people who will be asked about a site that is not theirs.
Nothing in the free plugin is reduced or held back without Ultra.
Distributed by WPDeveloper outside the WordPress plugin directory. It needs the free plugin, and does nothing without it.
What Ultra adds
Each one carries the rule it keeps, because what a security feature refuses to do matters as much as what it does. All of it is inert until you set something.
-
Two-factor and passkeys by role
Choose which roles have to hold a second factor or a passkey, and how long people have to set one up. Everyone sees how much of that grace period is left on every dashboard page, and when it runs out their next sign-in starts with the enrollment screen and carries straight on with the app they just set up.
Nobody is refused entry. The recovery link, and an administrator’s ability to switch a factor off for someone, are untouched.
-
Trusted devices
A checkbox on the code screen. The device is remembered for the number of days you set and the code screen is skipped on it, and people can see and revoke their own devices at any time.
Trust is forgotten when the password changes. Whoever manages the site sees which accounts hold a trusted device — who, and how many, never which.
-
The sign-in report
One table, by role: how many accounts, how many have two-factor, how many have a passkey, how many have neither, and how many the policy requires. Underneath it, who a policy is still waiting on. The role table exports as CSV.
Names stay here, on the screen where somebody can do something about them.
-
Sign-in screens in your name
Your logo, your accent color, your heading and your opening line on the code and enrollment screens, so the moment a client meets a security step it still looks like it came from you.
It changes how those screens look, never how they behave.
-
Alert channels
Slack and JSON webhooks, up to five destinations, each with its own floor: high and above, or critical only. There is a button that sends a test message, because an incident is the worst moment to find out an address was wrong.
As well as email, never instead. A channel can be quieter than email and never louder. Nothing is sent from a page a visitor loaded, a burst of events arrives as one message, and muted means muted.
-
The client report
A scheduled report for the people who pay for the site and never sign in to it: where it stands, what was put right, what happened, on the day of the month or week you pick. Your agency’s name on it, and the same logo and accent as the sign-in screens.
Written for a reader with no account: no links into a dashboard they cannot open, no names, and no next action addressed to them. Nothing is sold inside it. A quiet month says so and still goes out.
-
Temporary access
Administrator until Thursday, and then not. The grant records what the account held before, adds the role, and takes it back on its own. You can end it early, and every step of it is in the activity log.
It can only add. It never removes a capability somebody already had, and it never takes back the last administrator.
-
The automatic response
An advisory lands against a plugin at two in the morning. Ultra can install the publisher’s fix, or switch the plugin off while there is not one yet, and putting either back is one press. Before you arm it, it shows you what your rules would do to everything currently affected, and how often they would have fired over the last thirty days.
Nothing at all until you arm it. Never the security plugin itself, never during safe mode, never on stale advisory data, never on a visitor’s request, and at most three plugins in a run — with the record saying how many it left. Every action writes its way back before it happens.
-
A watch on the code nobody publishes
Every hour, Ultra looks at the code that has no official copy to be compared against: drop-ins, must-use plugins, the active theme, wp-config.php, .htaccess, and plugins the directory does not publish. When one of them changes, you hear about it.
It watches and tells you. It makes no claim to recognize malicious code, and it changes nothing on its own.
-
Explanations without a limit
Ask for any finding in plain language, as often as you want, through the AI provider you connected to WordPress. The free plugin puts a limit on how many; Ultra takes the limit off.
Your key stays yours. Neither plugin has anywhere to put one or ever sees it, and the question carries that finding’s recorded evidence and nothing else.
-
Ninety days of activity
The activity log reaches back 90 days instead of 30, with the same filtering, search and CSV export.
The window is checked every time the log is read, so it shows the tier the site is on right now rather than the one it was on last month.
Two licenses, both yearly
-
Unlimited sites
Everything on this page, on every site you look after. One license, one renewal, however many sites that turns out to be.
-
Single site
Everything on this page, on one site. The same add-on, the same features, one address.
The prices are set on the store rather than here. They will appear on this page, with a way to buy, as soon as the store is open.
How the license works
Everything described above runs from code in the add-on, and code in a GPL plugin runs whether or not a key was entered. What the license brings is updates and support: the site checks for a new version with your key, and you can ask the people who wrote it for help. That is the honest description of it, and it is the usual arrangement for a plugin licensed this way.
Activation, renewal and updates happen between your site and the store. The free plugin never names a license host and never asks you for a key.
A site with no valid license gets one calm line on the plugins screen. Nothing is switched off, and no banner follows you around the dashboard.
Turn the add-on off, or let the license lapse, and the site is back on the free tier on the very next request. Limits are checked when data is read as well as when it is written, so nothing is left reporting more than the tier allows. Anything you configured is kept as data, so coming back restores it.
What stays free
All of it. This list is the free plugin, and no part of it is smaller because Ultra exists.
- The security score, and every finding with its explanation and its evidence.
- One-click hardening, with an undo that puts back exactly what was there and never expires.
- Login protection and lockouts, and a way back in for whoever gets locked out.
- Two-factor with any authenticator app, single-use backup codes, and passkeys.
- The activity log — 30 days, filterable, searchable, exportable as CSV.
- The weekly summary, which arrives on quiet weeks too, and high or critical events emailed on their own.
- Safe mode and the recovery link that pauses every protection for an hour.
- Read-only abilities, so your own AI agent can ask about the site if you turn that on.
- Your files compared against the copies WordPress.org publishes, and one click to put one back.
The diagnosis is free and stays free, and there is never an upgrade prompt inside a security warning — not in the plugin, not in an alert, and not in anything Ultra sends to you or to your client.