WooCommerce security that stays out of the checkout
BetterShield looks after the accounts and code behind your store: customer and staff sign-ins, the files your plugins ship, and a record of who changed what. It adds nothing to the cart or checkout.
What actually goes wrong
Three things that go wrong on stores in particular.
-
My Account is a second sign-in page
A store with customer accounts has its own sign-in and sign-up forms, open to anyone. Scripts that guess passwords or make throwaway accounts find them as easily as the standard WordPress sign-in page.
-
Staff accounts reach orders and customers
The people who run the store sign in to the same dashboard as you, where orders, customer details and settings live. Unless you add a second step, a password is all that stands in front of them.
-
Changes go unnoticed
A store runs many plugins and updates them often. Without a record of what changed and who changed it, a new administrator or an altered file can sit for weeks before anyone looks.
How BetterShield helps a WooCommerce store
Protection for the accounts and code behind the store. Nothing is added to the cart or checkout, and only security events are recorded there.
-
A hidden bot check on store account forms
Refuse obviously automated submissions puts an invisible field and a clock on the sign-in, registration, comment and store account forms. Scripts that fill every field or submit within two seconds are refused, and people see nothing. On by default.
Login & Access guide -
Login limits on every account
Pause sign-in after repeated failures covers the My Account sign-in too. By default, 5 failed sign-ins in 15 minutes pause that connection for 15 minutes without locking the account. If the attempts named a real account, its owner is emailed an unlock link.
Login & Access guide -
Two-factor and passkeys on My Account
Customers set up two-factor, add passkeys and see where they are signed in on My Account › Sign-in security. For staff, Require two-factor of a role asks the roles you tick, with a 14-day grace period by default.
Two-factor and passkeys guide -
A record of who changed what
The activity log records sign-ins, account and role changes, password resets, and plugin, theme and core changes, with who and when. Filter, search and export to CSV, with 30 days of history. Edits to posts, pages and other content are not recorded.
Activity log guide -
A file check against the official copies
WordPress core and directory plugins are compared with the copies WordPress.org publishes, every hour and whenever a plugin is installed or updated. Your theme and plugins from outside the directory are watched for changes.
File check guide -
A way back in that leaves the shop open
Your recovery link pauses the sign-in protections for one hour and changes no setting. For an emergency, Lock the site down refuses sign-ins from every account that cannot manage the site, customers included, while the front end and checkout keep working.
Getting back in guide
6 ways people use it
Each one says when it applies and what to set up, or what to ask your assistant for.
- Store owners
Give customers a stronger sign-in
Customers keep their addresses and order history behind a password, and some want more than that.
- When
- Customers ask for two-factor, or you want to offer passkeys on their account page.
- Setup
- Nothing to switch on. My Account › Sign-in security lets each customer set up two-factor, add a passkey and see Where you are signed in, with Sign out everywhere except this device.
- Store owners
Put a second step in front of the dashboard
Staff accounts see orders and customer details. With two-factor, a password alone no longer opens them.
- When
- More than one person signs in to manage orders, products or settings.
- Setup
- Under Protect › Two-Factor, tick your staff roles in Require two-factor of a role. Each account gets 14 days to set it up by default, and your recovery link is checked first.
- Store owners
Cut the noise on sign-up and sign-in
Throwaway sign-ups and bursts of failed sign-ins fill the customer list and the log.
- When
- The customer list grows with accounts nobody uses, or the log shows repeated failed sign-ins.
- Setup
- Already on: Refuse obviously automated submissions, Pause sign-in after repeated failures and Slow repeated sign-ups, all under Protect › Login & Access. If a real customer is paused, Release now ends it.
- Developers
Check the files after an update
Plugins update often, and the theme or a custom plugin gets edited by hand now and then.
- When
- After updating plugins, or after someone has worked on the theme.
- Setup
- Open Activity › File changes. Show the difference shows each changed line in a core or directory plugin file, and Put the official file back keeps your copy in quarantine. Planned maintenance, under Settings › Email alerts, holds routine alerts while you work.
- Store owners
When something looks wrong during a sale
An account or a file you do not recognize turns up while orders are coming in.
- When
- Activity › Incidents has grouped related changes, such as a new administrator and a new PHP file on the same day.
- Setup
- Review timeline shows what joined and when. If everything needs to stop, Lock the site down under Protect › Recovery keeps the front end and checkout working, and Lift the lockdown ends it.
- Agencies
Ask an assistant instead of clicking through
You look after the store for someone else, or you would rather ask than open five screens.
- When
- You want a read on the store’s sign-in and files before a busy week.
- Setup
- Under Agents › Connect, turn on Let my agent read security information and Let an assistant connect to this site, and start read-only. Changes need the second switch, and a sign-in change waits for your yes.
The exact prompts to use
Connect your assistant under Agents › Connect, then paste any of these into Claude, ChatGPT or another assistant. The first two only read. The last two need the second switch on, and anything heavier than a fix with an undo waits for your yes.
Connect an AI assistant-
The store check-up
Read-onlyUsing BetterShield, read my store’s security score, grade and open findings. List the findings from most to least severe, and for each one tell me what it is, why it matters and what could break if I act on it. Do not change anything.
-
Who can run the store
Read-onlyUsing BetterShield, list every account on this store whose role is not Customer or Subscriber, with its role. Then read the activity log for the last 30 days and show me every account created, role changed, email changed or password reset requested, with who did it and when.
-
Before a sale
Can make changesUsing BetterShield, check that sign-in limits and the hidden bot check are on, and list the hardening fixes that are still off with what each would change. Apply the ones that can be undone right away. For anything that changes how people sign in, show me the plan and wait for my yes.
-
After updating plugins
Can make changesUsing BetterShield, show me which core and plugin files no longer match their official copies, and which plugins the activity log shows were installed or updated this week. If a changed file can be put back, show me the plan before you do it.
Or just ask your AI
BetterShield has an MCP server built in, off until you turn it on. Connect Claude, ChatGPT, Cursor, Codex or another assistant, and it can read your site’s security through 18 read-only abilities, which change nothing.
Changing is a second switch, off by default. With it on, a fix with an undo is applied straight away, and a change to how people sign in waits for you to agree in the conversation. Every call is recorded.
Never possible through a connection: creating accounts or credentials, changing recovery, two-factor or alert settings, lifting lockouts, or deleting log rows.
Connect an AI assistant See what assistants did on Agent activityWe have a sale this weekend. Is the store’s sign-in in good shape?
Used Get security posture → score 79 · grade B · 4 open findings
Used Get login protection settings → limit on · 5 in 15 minutes · bot check on
Used Get effective sign-in factor policies → two-factor required for no roles
Login limits and the hidden bot check are on. No role has to use two-factor yet, so staff accounts rely on their passwords: you can require it under Protect › Two-Factor, which I cannot change. One open finding has a fix with an undo, so I can apply that now.
Used Apply a protection → Stop publishing the WordPress version · undo kept
Frequently asked questions
Does BetterShield change my WooCommerce cart or checkout?
No. BetterShield adds nothing to the cart or checkout pages. On them it adds no bot check, skips its sampling, checks and housekeeping, and only records security events.
Can WooCommerce customers use two-factor and passkeys?
Yes. Each customer can set up two-factor with any authenticator app, add passkeys and see where they are signed in from My Account › Sign-in security. Passkeys need HTTPS, and a customer signs in with one on the site’s own sign-in page (wp-login.php), which shows the Sign in with a passkey button.
Can I require two-factor for every customer?
No. Require two-factor of a role is asked in the dashboard, and customers are sent to My Account instead, so it does not ask them. They can still set it up themselves on My Account › Sign-in security. Use the requirement for the roles your staff sign in with.
Will the hidden bot check get in a real customer’s way?
People see nothing and solve nothing. It is an invisible field and a clock, and it refuses only submissions that fill the hidden field or arrive within two seconds of the form. It is on by default, and Refuse obviously automated submissions under Protect › Login & Access turns it off.
What happens when a customer gets their password wrong too many times?
By default, 5 failed sign-ins in 15 minutes from one connection pause sign-in from that connection for 15 minutes. The account itself is not locked, and if the attempts named a real account, its owner is emailed an unlock link. Release now, under Lockouts, ends a pause early.
Does BetterShield scan the store for malware or vulnerable plugins?
No. It has no firewall, does not scan for or remove malware, and its check against published vulnerability advisories has no data source connected in this version. It compares WordPress core and directory plugins with the official copies, watches your theme and other code for changes, and flags directory plugins that are closed or have had no update for two years.
Keep reading
- Guide
Set up sign-in protection on Login & Access
Set BetterShield’s login attempt limits, hidden bot check, public form limits, allow and block lists, trusted proxies and session limits. - Guide
Set up two-factor sign-in and passkeys
Turn on two-factor sign-in with an authenticator app and backup codes, add passkeys, require them by role, and help a user who lost their device. - Blog
WordPress file integrity check: compare with the official copies
A WordPress file integrity check compares core and plugin files with the copies WordPress.org publishes. How BetterShield runs one, and what to do next.
Close the open doors today
Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.
Requires WordPress 6.7 or newer and PHP 8.0 or newer.