BetterShield
All use cases Page-builder sites

Security for Elementor and other page-builder sites

BetterShield compares the add-ons you installed from WordPress.org with their official copies, watches your theme and premium add-ons for changes, and records every install and update.

What actually goes wrong

Three things that go wrong on sites built with a page builder.

  • Many add-ons, many authors

    A builder site often runs the builder, a few add-on packs, a forms plugin and a theme, each from a different author and each updating on its own schedule. Nobody keeps a list of what changed, or when.

  • Premium code has no official copy

    WordPress.org publishes checksums for the plugins in its directory. Add-ons bought elsewhere, and themes, have none, so a changed file there looks like every other file unless something recorded what it was before.

  • Code can be edited from the dashboard

    WordPress gives administrators plugin and theme code editors in the dashboard. A quick change made there goes straight into the code the site runs, and on a site several people manage, nobody else may know.

How BetterShield helps a page-builder site

Add-ons from the WordPress.org directory are compared with the copies WordPress.org publishes. Premium add-ons and the theme have no such copy, so they are watched for changes, and the report says which is which.

  • Directory add-ons against the official copies

    WordPress core and plugins from the WordPress.org directory are compared with the copies WordPress.org publishes, every hour and whenever a plugin is installed or updated. Show the difference shows the changed lines, and Put the official file back keeps your copy in quarantine.

    File check guide
  • Premium add-ons and the theme, watched

    WordPress.org publishes no checksums for premium or custom plugins, or for themes. Their code files are recorded at the first check, and later changes are reported, except an update WordPress itself installed. Premium plugins are named in the report’s note, and a changed file is listed under No official copy to put back, so keep your own backups.

    File check guide
  • A record of every install and update

    The activity log records plugin and theme installs, updates, activations, deactivations and deletions, with who and when. When a plugin from outside the directory updates, it notes which code files the update added or changed. Filter, search and export to CSV, with 30 days of history.

    Activity log guide
  • Add-ons that stopped getting updates

    Findings names directory plugins that WordPress.org has closed, and those with no update there for two years, with the last-updated date the directory gives. It reads nothing into either. Explain says why it matters and what could break, and keeping or replacing the plugin is yours to decide.

    Score and findings guide
  • The dashboard code editors, switched off

    Disable the dashboard file editor removes the built-in plugin and theme code editors from the dashboard. Files stay editable over SFTP and through your host. It is one of Quick Setup’s safe fixes, and the finding The dashboard file editor is enabled has an Apply fix button.

    Hardening guide
  • See what a content policy would block, first

    Find out what a content policy would break sends a report-only policy on front-end pages, so nothing is blocked. What the policy would have blocked names each rule and the origin it would have stopped, most frequent first. Start enforcing this policy is offered only after 7 days with no reports.

    Security headers guide

6 ways people use it

Each one says when it applies and what to set up, or what to ask your assistant for.

  • Designers

    Edit the theme on purpose, and mark it expected

    You or a developer changed a template file in the theme by hand, and the file check now reports it.

    When
    Activity › File changes lists theme files under No official copy to put back after work you know about.
    Setup
    Check the path and when it was Noticed, then press Expected. It stops reporting the file as it is now, and a further change is reported again. For a batch, Mark all 12 changes expected… under By plugin and version (the button shows your count) names any added files that can run as code first.
  • Developers

    Check the add-ons after an update round

    The builder, its add-ons and the theme update on their own schedules, sometimes all on the same afternoon.

    When
    After a round of plugin and theme updates.
    Setup
    On Activity › Site activity, choose Updates & extensions to see each install and update with who and when, including the code files an update added or changed in a plugin from outside the directory. Then open Activity › File changes, where Check again closes changes that match the installed version’s published copy.
  • Site owners

    Decide about an add-on nobody updates

    An add-on installed for one page years ago is still active, and nobody remembers why.

    When
    Findings shows An installed plugin is no longer in the WordPress.org directory, or An installed plugin has had no update in the WordPress.org directory for years.
    Setup
    Press Explain for Why it matters and What could break, then check the plugin’s page and its author’s own site. Keeping, replacing or removing it is yours to decide. For a known reason to wait, Remind me later snoozes it for 7 or 30 days.
  • Developers

    Try a fix before it changes anything

    The site depends on plugins you did not write, and you want to know what a hardening fix touches before it is live.

    When
    Before turning on a fix on Protect › Hardening, or under Signing in on Protect › Login & Access.
    Setup
    Press Preview the change: it lists what applying would do and changes nothing. For Disable XML-RPC and four Signing in fixes, Monitor first counts the real requests that would have matched over 1 hour, 24 hours or 7 days, then Enforce reviewed settings. A match is not proof of breakage, and no matches is not proof of safety.
  • Site owners

    See what your pages load from elsewhere

    A page can load fonts, scripts, maps and videos from other addresses, and on a site built from many add-ons nobody has the full list.

    When
    You are thinking about a content policy, or you only want the list.
    Setup
    Turn on Find out what a content policy would break under What browsers are told on Protect › Hardening. Nothing is blocked. Read What the policy would have blocked over a week of normal traffic. Start enforcing this policy unlocks only after 7 days with no reports, and Go back to watching returns to report-only at once.
  • Agencies

    Hand a client site over with the code editors off

    The client gets an administrator account, and the theme and add-ons should stay as you delivered them.

    When
    Before handing over a site, or when someone new is given full access.
    Setup
    Turn on Disable the dashboard file editor under What can run on Protect › Hardening, or keep Turn off the file editor ticked in Quick Setup’s Safe fixes. Then, under Where alerts go in Settings › Email alerts, add your own address beside the client’s, so alerts about an altered file reach you.

The exact prompts to use

Connect your assistant under Agents › Connect, then paste any of these into Claude, ChatGPT or another assistant. The first two only read. The last two need the second switch on, and putting a file back waits for your yes.

Connect an AI assistant
  • The add-on check-up

    Read-only

    Using BetterShield, read my open findings and pick out the ones about plugins: closed on WordPress.org, no update in the directory for years, code in the plugins folder that no installed plugin claims, or files that no longer match the official copies. For each, tell me why it matters and what could break if I act on it. Do not change anything.

  • After an update round

    Read-only

    Using BetterShield, read the activity log for the last 7 days and list every plugin and theme installed, updated, activated or deleted, with who did it and when, and any note that an update added or changed code in a plugin outside the directory. Then read the file check and tell me which open changes are in directory plugins and which are in the theme or in plugins with no official copy. Do not change anything.

  • Close the code editors, start the content report

    Can make changes

    Using BetterShield, check whether “Disable the dashboard file editor” and “Find out what a content policy would break” are on. Turn on whichever is off, tell me how to undo each, and leave anything that changes how people sign in alone.

  • Put a changed add-on file back

    Can make changes

    Using BetterShield, list the open file changes. For a file in WordPress core or a directory plugin that no longer matches its official copy, show me the plan to put the official file back and wait for my yes. For changes in the theme or in plugins with no official copy, list them by path and change nothing.

Or just ask your AI

BetterShield has an MCP server built in, off until you turn it on. Connect Claude, ChatGPT, Cursor, Codex or another assistant, and it can read your site’s security through 18 read-only abilities, which change nothing.

Changing is a second switch, off by default. With it on, a fix with an undo is applied straight away, and a change to how people sign in waits for you to agree in the conversation. Every call is recorded.

Never possible through a connection: creating accounts or credentials, changing recovery, two-factor or alert settings, lifting lockouts, or deleting log rows.

Connect an AI assistant See what assistants did on Agent activity
Your assistant yoursite.example · changes allowed

I updated the builder and five add-ons this morning. Is everything as it should be?

Used Query activity → 6 plugins updated today · 1 note: an update added or changed code in an unlisted plugin

Used Get integrity status → 1 open change in a directory plugin · 2 plugins not comparable

Used Get saved hardening state → Disable the dashboard file editor: off

All six updates are in the log, with who ran them. For the add-on from outside the directory, the log also names the code files its update added or changed. One file in a directory plugin no longer matches its official copy, so read the difference on Activity › File changes first. Two plugins have no official copy, so they are watched for changes instead. The dashboard file editor is still on, and I can turn it off now.

Used Apply a protection → Disable the dashboard file editor · undo kept

Putting the official copy of that file back, with yours kept in quarantine, waits as a plan for your yes.
Illustration. The tool names are the ones BetterShield gives your assistant.

Frequently asked questions

Can BetterShield check premium plugins and add-ons?

It watches them, but it cannot compare them with an official copy. WordPress.org publishes no checksums for premium or custom plugins, or for themes, so their code files are recorded at the first check and later changes are reported, except an update WordPress itself installed. Activity › File changes names premium plugins in its note and lists a changed file under No official copy to put back, so restore it from your own backup. When one updates, the activity log notes which code files the update added or changed.

Will a normal plugin update show up as a file change?

Not normally. A directory plugin is compared with the checksums for the version installed, and an update WordPress itself installed is not reported for watched code. If changes remain from the version you had before, Check again under By plugin and version closes the ones that match.

Does BetterShield flag add-ons nobody maintains anymore?

For plugins listed in the WordPress.org directory, yes. Findings names any the directory has closed, and any with no update there for two years, with the last-updated date the directory gives, and reads nothing into either. It asks WordPress.org about a few plugins each day, so on a site with many it takes some days to cover them all. Before you add another, Plugins › Add Plugin shows No update since and the date beside the Install button of a plugin with no update for two years.

Will the content policy report change what visitors see?

No. Find out what a content policy would break sends the policy in report-only mode on front-end pages, so nothing a visitor loads changes, and browsers only report what would have been blocked. Start enforcing this policy is offered only once nothing has been reported for 7 days, and asks you to confirm. Go back to watching returns to report-only at once.

What does turning off the dashboard file editor change?

Disable the dashboard file editor removes the built-in plugin and theme code editors from the dashboard. Files stay editable over SFTP and through your host. If wp-config.php already disables the editor, or on a multisite network, it changes nothing. Preview the change shows what applying would do, and turning the switch off undoes it.

Does BetterShield scan add-ons for malware or known vulnerabilities?

No. It has no firewall, does not scan for or remove malware, and its check against published vulnerability advisories has no data source connected in this version. It compares WordPress core and directory plugins with the official copies, watches the theme and other code for changes, and flags directory plugins that are closed or have had no update for two years.

Keep reading

All use cases

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield