Title: BetterShield – Security Audit, 2FA, Passkeys &amp; Login Protection
Author: WPDeveloper
Published: <strong>13. септембар 2026.</strong>
Last modified: 5. октобар 2026.

---

Претражи додатке

![](https://ps.w.org/bettershield/assets/banner-772x250.png?rev=3729390)

![](https://ps.w.org/bettershield/assets/icon-256x256.png?rev=3729390)

# BetterShield – Security Audit, 2FA, Passkeys & Login Protection

 Аутор: [WPDeveloper](https://profiles.wordpress.org/wpdevteam/)

[Преузимање](https://downloads.wordpress.org/plugin/bettershield.1.1.0.zip)

 * [Детаљи](https://sr.wordpress.org/plugins/bettershield/#description)
 * [Рецензије](https://sr.wordpress.org/plugins/bettershield/#reviews)
 *  [Постављање](https://sr.wordpress.org/plugins/bettershield/#installation)
 * [Развој](https://sr.wordpress.org/plugins/bettershield/#developers)

 [Подршка](https://wordpress.org/support/plugin/bettershield/)

## Опис

Most security plugins tell you whether your WordPress site is protected. BetterShield
goes a step further: it tells you what it checked and what it found, and fixes the
issues for you.

**BetterShield** is a WordPress security plugin by WPDeveloper. It audits your site,
explains every finding **in plain language**, fixes what it can in one click with
your approval, and gives every fix an undo that never expires. Two-factor authentication(
2FA), passkeys, login protection, an activity log, incident response, a lockout 
recovery link and a built-in MCP connector for AI assistants are included. No account
and no sign-up needed.

#### Why site owners choose BetterShield

 * **Finds security problems AND fixes them, with your approval.** A _54-check audit_
   scores your site, and sixteen one-click fixes close the gaps. Nothing changes
   until you choose a fix.
 * **Every fix has an undo that never expires.** Change your mind months later and
   undo it in one click.
 * **Ask an AI assistant what needs fixing.** Claude, ChatGPT, Cursor and other 
   assistants can read your site’s security through the built-in MCP server, off
   until you turn it on.
 * **Every site in one Hub.** See and fix every site you look after in one place.
 * **Nothing leaves your site unless you choose it.** Out of the box, the only outside
   services contacted are WordPress.org’s own, asked about your files and plugins.
   Usage sharing, the leaked-password check, your AI provider and BetterShield Hub
   are each off until you turn them on.
 * **Honest results.** A file that was never compared, or a check that could not
   run, is never reported as clean.
 * **Performance you can see.** The Overview shows the queries and milliseconds 
   BetterShield added to real page views.
 * **The essentials are FREE.** The full audit, all 16 fixes with undo, 2FA, passkeys,
   the activity log, the file integrity check and alerts.

#### Quick Setup

A short Quick Setup Wizard opens once after activation. It offers **5 hardening 
fixes** that cannot lock anyone out, makes sure you have a way back in (a **single-
use recovery link** emailed to the admin address, plus printable recovery codes),
and lets you choose which plugin handles which job if another security plugin is
active. Skip it, or run it again from Settings > General.

#### WordPress Security Audit: 54 checks that act when you approve

Fifty-four read-only checks cover access, exposure, updates, extensions, server 
settings and configuration, including:

 * Idle “Admin” accounts nobody has used in over six months
 * User enumeration, XML-RPC, the file editor and the WordPress version on every
   page
 * Missing security headers, an outdated PHP version and weak security keys
 * Plugins closed on WordPress.org, or with no update for years
 * Installer or database tools left in the web root after a migration
 * A domain without SPF, DMARC or CAA records
 * Core and plugin files that no longer match the official copies

Each finding explains what it is, why it matters and what could break if you act
on it. Not ready yet? Snooze it for 7 or 30 days.

#### One-click hardening: 16 fixes, each with a permanent undo

Each fix shows what it will change before you apply it and stays off until you do.
A fix your hosting cannot support, such as .htaccess rules on a server that is not
Apache, cannot be switched on, and the screen tells you why.

The sixteen one-click fixes:

 * Disable XML-RPC
 * Disable the dashboard file editor
 * Block public user listing (user enumeration)
 * Stop PHP running in uploads
 * Stop uploads directories listing their contents
 * Hide sensitive files from visitors
 * Change the sign-in address (custom login URL)
 * Refuse application passwords
 * Refuse passwords found in known breaches
 * Keep low-privilege accounts out of the dashboard
 * Hide the dashboard from visitors
 * Stop publishing the WordPress version
 * Strengthen and rotate the sign-in keys
 * Tell browsers to refuse plain HTTP (HSTS)
 * Find out what a content security policy (CSP) would break, before you enforce
   one
 * Send security response headers

#### AI explanations and AI assistants (MCP)

 * With an AI provider connected under Settings > Connectors (WordPress 7.0 or newer),
   explain any finding in plain language, or ask Explain my audit for a summary.
 * The MCP server lets Claude, ChatGPT, Cursor, Codex and other assistants read 
   your site’s security through eighteen bounded, read-only abilities. It is off
   until you turn it on under **Agents > Connect.**
 * A second switch, off by default, lets an assistant apply and undo fixes.
 * **Never possible through a connection:** creating accounts or credentials, changing
   recovery, two-factor or alert settings, lifting lockouts, or deleting log rows.

#### Using BetterShield with another security plugin

BetterShield works alongside the security plugin you already have, and makes sure
the two do not do the same job twice. Switching over completely? It can bring over
settings from Kadence Security, All-In-One Security, Really Simple Security or Wordfence,
with a preview first and an undo.

#### Two-factor authentication (2FA) and passkeys

For yourself, the roles you choose or your WooCommerce customers:

 * **Two-factor with any authenticator app** and ten single-use backup codes, never
   enforced until the app is proven to work.
 * **Require two-factor by role**, with a 14-day grace period by default.
 * **Passkeys:** sign in with a fingerprint, face or device PIN. Only the public
   half of the key is stored.
 * **Passkey-only sign-in by role,** once a working recovery option is in place.

#### Login protection and brute force defense

 * **Limit login attempts:** by default, 5 failed sign-ins in 15 minutes pause that
   connection for 15 minutes, doubling with each repeat within a day.
 * **A hidden bot check** on the login, registration, WooCommerce account and comment
   forms.
 * **Limits on public forms:** comment bursts wait in moderation, and repeated password
   resets or sign-ups are paused.
 * **Strong password rules**, an optional leaked-password check, an IP and username
   blocklist, and an allowlist that is never locked out.

#### Lockout recovery

Locked out? Get back in without FTP or a call to your host. A single-use recovery
link, emailed when you activate BetterShield, pauses its sign-in protections for
one hour and leaves your settings as they are. Printed recovery codes are a second
way in.

#### Security activity log

Sign-ins, account and role changes, password resets, and plugin, theme and core 
changes, with who and when. **Filter, search and export to CSV, with 30 days of 
history.** Each finished day is sealed, so an edit or deletion opens a high-severity
finding.

#### Incident response

Related access and file changes are joined into one incident, with signs of an account
takeover flagged. You review the response plan before anything changes, and BetterShield
checks again afterwards.

#### Security alerts

**A weekly summary that arrives on quiet weeks too,** and high or critical events
emailed on their own. No message ever contains an upgrade prompt.

#### File integrity check against WordPress.org

WordPress core and directory plugins are compared with the official copies WordPress.
org publishes, showing exactly which lines changed. One click puts the official 
file back, and the replaced file is kept, never deleted. Your theme, drop-ins, wp-
config.php, .htaccess and other unpublished code are watched for changes.

#### BetterShield Hub (Multisite Control)

An optional dashboard for people who look after more than one site. Connect sites
from BetterShield > Hub to see every score and finding in one place, apply or undo
fixes across sites with nothing changing until you agree, get alerts when a site
goes down or its grade drops, and invite your team. Everything in BetterShield works
without the hub.

#### Built for agencies and many sites

 * WP-CLI commands for audits, findings, hardening, activity, recovery, file checks
   and settings
 * Settings export and import, with a preview and an undo
 * Multisite: every site’s score in one table, and two-factor and passkey rules 
   set once for the network

#### BetterShield Ultra [Pro]

Ultra is a separate paid add-on for people who look after sites for others. It needs
the free plugin and is not on sale yet. It will add:

 * Two-factor set-up at sign-in for the roles you choose
 * Trusted devices and a sign-in report by role
 * Branded two-factor screens
 * Slack and webhook alerts
 * A scheduled client report
 * Temporary access that ends on its own

### Backed By a Team You Trust

BetterShield is developed by the trusted team at **[WPDeveloper](https://wpdeveloper.com/),**
a leading WordPress product company used and loved by 6 million users and businesses.

### External services

BetterShield contacts six outside addresses, and a seventh, BetterShield Hub, reaches
it only if you connect the site to the hub. It contacts four addresses operated 
by WordPress.org, all to check that your files still match the official ones and
to put an official file back if you ask. It contacts your own AI provider only if
you have connected one, the Pwned Passwords service only if you switch on the breached-
password check, and the usage service only if you choose to share usage data.

**api.wordpress.org** — the published checksums for your WordPress version, when
the file check runs on its schedule or when you start one; the request carries your
WordPress version and language. Once a day it also asks whether the directory still
lists a few of the plugins you installed from it; that request carries the plugin’s
slug only. Plugins you choose to install in the Quick Setup’s optional last step
are fetched by WordPress’s own installer, from here and downloads.wordpress.org.

**downloads.wordpress.org** — the published checksums for a directory plugin at 
the exact version you have, during the same check and whenever a plugin is installed
or updated, including automatic updates. The request carries the plugin’s slug and
version.

**core.svn.wordpress.org** and **plugins.svn.wordpress.org** — the official copy
of one file, fetched only when you press Restore on a changed file. The request 
carries the version and the file’s path, and the copy is checked against the published
checksum before anything is written.

**api.pwnedpasswords.com** — the Pwned Passwords service by Have I Been Pwned, only
if you switch on “Refuse passwords found in known breaches”, and only when someone
signed in to your site sets or changes a password. The password is hashed on your
server and only the first five characters of the hash are sent; the comparison happens
on your server. No password, account name, email, site address or identifier is 
sent. Documentation: https://haveibeenpwned.com/API/v3#PwnedPasswords — privacy 
policy: https://haveibeenpwned.com/Privacy

**send.wpinsight.com** — WPDeveloper’s usage service, only if you choose to share
usage data (Get Started on the first Quick Setup step; Skip sends nothing). At most
once a day, and once when you deactivate BetterShield, it sends your site address
and title, administrator email, WordPress, PHP and web server versions, language
settings, whether the site is multisite, the installed and active plugins, your 
theme and its version, BetterShield’s version and folder name, and the report reference.
Never anything about your visitors, users, sign-ins or findings. Turn it off under
Settings > General. Privacy policy: https://wpdeveloper.com/privacy-policy

**BetterShield Hub** (hub.bettershield.ai, or the address you set under BetterShield
> Hub), only if you connect the site and approve it on this site’s own consent page.
The hub then reads the score, findings and available tools, and applies or removes
a protection when you ask, under the same rules as an AI assistant. This site does
not contact the hub; the hub contacts the site and checks every few minutes that
its front page answers. Disconnect ends it at once.

**Your own AI provider**, only if you have connected one to WordPress and only when
you ask for an explanation. WordPress sends the request through your connector under
Settings > Connectors; BetterShield never sees, asks for or stores the key. It sends
the finding’s title, severity, description and recorded evidence, with web and email
addresses stripped, and never file contents, usernames, keys or your site’s address.

None of the WordPress.org requests carries anything about your site: no site address,
email, username, IP address, keys, file contents or identifier. They happen on a
schedule, when you press a button, or when a plugin is installed or updated, never
while a visitor loads a page. If a service cannot be reached, the check says it 
could not run rather than reporting a file as unchanged.

The four WordPress.org addresses are provided by the WordPress Foundation. Terms
of use: https://wordpress.org/about/privacy/ and https://wordpress.org/about/privacy/
cookies/

**Published vulnerability advisories** — not contacted in this version. No data 
source is connected, and the Findings screen says so. When one is, this section 
will name it and say what is sent, and the check will stay off until you turn it
on.

### What it keeps about people

Everything BetterShield keeps about a person stays on your own server: activity 
log rows, sign-in attempts, passkeys and account records, with IP addresses truncated
to a network before they are stored. The FAQ above describes each record. Tools 
> Export Personal Data and Tools > Erase Personal Data both support BetterShield,
and Tools > Site Health > Info lists every record, why it is kept and for how long.

### Source code

Everything that runs is readable in the plugin folder. The PHP in `src/` is not 
generated, compiled or minified. The admin interface is compiled into `assets/build/`(
scripts, stylesheets and small generated PHP files that list each script’s dependencies)
from the sources in `assets/js/` and `assets/css/`, which ship next to it. To rebuild,
run `npm install` and then `npm run build`, which uses @wordpress/scripts from the
included `package.json`.

## Снимци екрана

[⌊The Overview after the first audit: the score, the three fixes worth doing first,
and what changed since your last visit.⌉⌊The Overview after the first audit: the
score, the three fixes worth doing first, and what changed since your last visit
.⌉[

The Overview after the first audit: the score, the three fixes worth doing first,
and what changed since your last visit.

[⌊Every finding with its severity, why it matters, and a fix or a reason to mark
it not applicable.⌉⌊Every finding with its severity, why it matters, and a fix or
a reason to mark it not applicable.⌉[

Every finding with its severity, why it matters, and a fix or a reason to mark it
not applicable.

[⌊One-click hardening. Each item previews what will change and has an undo that 
never expires.⌉⌊One-click hardening. Each item previews what will change and has
an undo that never expires.⌉[

One-click hardening. Each item previews what will change and has an undo that never
expires.

[⌊Login protection: how the site sees a connection, attempt limits, lockouts, and
the addresses always allowed or never allowed.⌉⌊Login protection: how the site sees
a connection, attempt limits, lockouts, and the addresses always allowed or never
allowed.⌉[

Login protection: how the site sees a connection, attempt limits, lockouts, and 
the addresses always allowed or never allowed.

[⌊The activity log: who did what and when, with filters, search and a CSV export.⌉⌊
The activity log: who did what and when, with filters, search and a CSV export.⌉[

The activity log: who did what and when, with filters, search and a CSV export.

[⌊Files compared against the copies WordPress.org publishes, with the difference
shown and one click to put a file back.⌉⌊Files compared against the copies WordPress.
org publishes, with the difference shown and one click to put a file back.⌉[

Files compared against the copies WordPress.org publishes, with the difference shown
and one click to put a file back.

## Постављање

 1. In your dashboard, go to Plugins > Add Plugin, search for „BetterShield“, then 
    install and activate it. Or upload the folder to `/wp-content/plugins/bettershield`.
 2. On activation, a read-only security audit runs, your recovery link is emailed to
    the site’s admin address, and the Quick Setup opens.
 3. Open **BetterShield** in the admin menu to see your score and findings.

No hardening fix, required two-factor or passkey-only sign-in is switched on **until
you choose it.** A few protections start at activation, and each can be switched
off:

 * Login attempt limits
 * A hidden bot check on the login, registration, WooCommerce account and comment
   forms
 * Limits on the comment, password reset and sign-up forms
 * Minimum password lengths
 * Weekly and instant email alerts

## ЧПП

### Is BetterShield free?

Yes. The audit, every plain-language explanation, all 16 fixes and their undo, two-
factor authentication, passkeys, login protection, the recovery link, the activity
log, incident response, the file check and the MCP server are free. There is no 
account and no payment. BetterShield Ultra, a separate add-on for agencies, is coming
soon and adds extras such as AI client drafts, a network-wide Incidents tab and 
longer history.

### Does BetterShield include a firewall or malware scanner?

No. BetterShield does not include a firewall and does not scan for or remove malware.
It audits your configuration, hardens it with fixes you can undo, secures logins,
logs activity, groups suspicious changes into incidents, compares WordPress core
and directory plugins with the official WordPress.org copies, and watches your theme
and the files nobody publishes for changes.

### Can I use BetterShield alongside another security plugin?

Yes, with care. If another security plugin is active, the Quick Setup asks which
plugin should keep each shared job, such as login limits, so they are not both doing
it. On the Hardening screen, a fix another plugin already covers says so. It does
not catch every overlap, so check the other plugin’s settings too, and avoid turning
on login or two-factor features in both.

### How do I switch from another security plugin?

Install BetterShield and let the first audit run; it changes nothing. If you are
coming from Kadence Security, All-In-One Security, Really Simple Security or Wordfence,
Settings > General can bring over their protections and sign-in attempt limits. 
You see a preview first, it lists what it could not carry and why, the other plugin
is only read, and the import can be undone. Then apply any other fixes you want 
one at a time and switch the old plugin’s features off as you go.

### Will the fixes break my site?

Every fix can show you what it will change before you apply it, and each can be 
undone at any time. Where an undo cannot reach everything, the fix says so first:
people signed out by a key change stay signed out, and browsers that already saw
the HSTS header keep insisting on HTTPS until it expires.

### What happens if I lock myself out?

Open your latest recovery link and press its one button. BetterShield’s sign-in 
protections pause for one hour and your settings stay exactly as they are. You can
generate a fresh link from Protect > Recovery at any time; generating one stops 
the old one working. Using a link issues the next one straight away, on the page
and by email. A link you never use stops working after 90 days, and BetterShield
warns you in the last two weeks. Printed recovery codes are a second way back in.

### Can two-factor authentication lock my users out?

Not by setting it up. Nothing is enforced until the app is proven to work and the
backup codes are saved, and required two-factor comes with a grace period (14 days
by default). If someone loses their phone, a backup code signs them in, and an administrator
can turn two-factor off for them.

### Will it slow down my site?

The Overview measures it and shows the number for your own site. For visitors, BetterShield
runs the fixes you turned on, its login protection on sign-in, the limits on the
comment, reset and sign-up forms, and a hidden bot check on the sign-in, registration
and comment forms. Audits, file checks and emails never run inside a visitor’s page
view. On the WooCommerce cart and checkout, BetterShield adds no bot check, skips
its sampling, checks and housekeeping, and only records security events.

### Does it send my data anywhere? Do I need an account?

There is no account. Out of the box, BetterShield contacts WordPress.org only, to
check your files and plugins, and those requests carry version numbers and plugin
slugs, never your site address, email or username. Everything else is off until 
you turn it on: usage sharing (the first Quick Setup step), the leaked-password 
check, your own AI provider, and BetterShield Hub. External services below lists
exactly what each one sends.

### What does BetterShield keep about people?

Everything is stored on your own server. The main records:

 * **Activity log:** what happened and who did it, with IP addresses truncated to
   a network before storage. Rows are removed after thirty days.
 * **Sign-in attempts:** the username tried, the outcome, the truncated network 
   and a keyed digest of the IP address, used for lockout decisions and pruned aggressively.
 * **Passkeys:** the device name you gave, when it was added and when it was last
   used. Only the public half of the key is stored.
 * **Account records:** two-factor setup, backup codes, password-policy status, 
   two-factor deadlines and last sign-in.

Tools > Export Personal Data and Tools > Erase Personal Data both support BetterShield.
A few security records are kept on purpose, and the erasure result says so: the 
date the account last signed in, lockout records, incident evidence and assistant
activity. Tools > Site Health > Info lists every record, how long it is kept, and
what erasure does to it.

### Does BetterShield detect vulnerable plugins?

Not yet. The check against published vulnerability advisories is built, but no data
source is connected in this version, and the Findings screen says so rather than
showing an empty list as a clean result. Today BetterShield flags plugins the WordPress.
org directory has closed or that have had no update for years, and its file check
shows any core or directory plugin file that no longer matches the official copy.

### Is the activity log tamper-proof?

No, and it does not claim to be. It is tamper-evident: each finished day is sealed
and chained to the day before. If a sealed day is later edited or deleted, the next
daily check opens a high-severity finding.

### Can an AI assistant change my site?

Only if you let it. The MCP connection is off until you turn it on under Agents 
> Connect, and reading and changing are separate switches. With only reading on,
an assistant can look and change nothing. With changing on, it can apply and undo
fixes and put a changed file back, and every change has an undo and is recorded 
in the activity log. A connection can be issued read-only whatever the switches 
say. Creating accounts or credentials, changing your recovery options, two-factor
or alert settings, lifting lockouts and deleting log rows are never possible through
a connection. Agents > Surface shows which abilities on your site, from any plugin,
can make changes.

### Do I need BetterShield Hub?

No. It is optional, and everything in the plugin works without it. The hub is for
people who look after several sites and want their scores, findings and fixes in
one place. You connect each site from its own BetterShield > Hub screen and approve
it on that site. To end the connection, press Disconnect on the site: removing a
site inside the hub does not end it.

### What can BetterShield Hub see and change?

What you allow when you connect. Read-only lets it see the score, findings and a
few security views, such as administrators by display name and role. Read-and-fix
also lets it apply and undo fixes; each change shows the site’s own plan first and
waits for someone in your hub team to agree. Connecting turns on the plugin’s assistant
connection if it is off, and the consent page has „Allow it to change this site“
ticked by default, so untick it if you want read-only. Every change the hub makes
is recorded in the site’s activity log.

### Does it work with WooCommerce?

Yes. Customers can set up two-factor, add passkeys and see where they are signed
in from a Sign-in security tab on My Account. BetterShield adds nothing to the cart
or checkout pages.

### Does it work on multisite?

Yes. Each site keeps its own findings, settings and fixes. The network admin gets
every site’s score and open findings in one table, 200 sites at a time, two-factor
and passkey rules set once as a floor under every site, and a recovery link for 
the network.

### What happens if I delete the plugin?

Its records stay by default, including the activity log, findings and undo history,
so reinstalling picks up where you left off. Fixes it applied, including .htaccess
rules, stay applied too, so undo anything you do not want to keep before you delete.
Under Settings > General, „If this plugin is ever deleted“ can instead remove this
plugin’s records, which also takes its server rules back off.

Copies of files it replaced are kept in `wp-content/uploads/bettershield-quarantine/`,
because the version that was there may be exactly what somebody put on your site,
and deleting it on the way out is not a decision this plugin makes for you. Remove
them one at a time from Activity > Files before you delete the plugin, or delete
the folder yourself afterwards. A third setting does both for you: it packages the
copies into one zip file inside `wp-content/uploads/bettershield-quarantine/`, takes
the copies away only once that archive has been written, and then removes this plugin’s
records as above. Nothing serves that archive, since the folder it is written into
refuses to hand anything out, so collect it the way you would any other file on 
the site, over SFTP or from your host’s file manager.

## Рецензије

Нема рецензија за овај додатак.

## Сарадници и градитељи

„BetterShield – Security Audit, 2FA, Passkeys & Login Protection“ је софтвер отвореног
кода. Следећи људи су допринели овом додатку.

Сарадници

 *   [ WPDeveloper ](https://profiles.wordpress.org/wpdevteam/)

[Преведите „BetterShield – Security Audit, 2FA, Passkeys & Login Protection“ на свој језик.](https://translate.wordpress.org/projects/wp-plugins/bettershield)

### Заинтересовани сте за развој?

[Прегледајте кôд](https://plugins.trac.wordpress.org/browser/bettershield/), погледајте
[SVN складиште](https://plugins.svn.wordpress.org/bettershield/) или се претплатите
на [дневник развоја](https://plugins.trac.wordpress.org/log/bettershield/) преко
[RSS-а](https://plugins.trac.wordpress.org/log/bettershield/?limit=100&mode=stop_on_copy&format=rss).

## Дневник измена

#### 1.1.0 – 05/10/2026

 * Added: Usage Data | Optional usage data sharing, asked once in Quick Setup and
   switchable under Settings > General
 * Added: Overview | See which checks opened, passed, changed severity or were marked
   not applicable since an earlier day, with the score then and now
 * Added: Security Audit | Four new checks: unfiltered code below administrator,
   script uploads below administrator, this plugin’s automatic updates switched 
   off, and world-writable folders under wp-content
 * Added: Recovery | Checks that a recovery link or printed code works before any
   change to how people sign in, from the dashboard or `wp bettershield harden` (`--
   force` to go ahead)
 * Added: Incidents | An email change, a password change and a new application password
   on one privileged account within an hour are recorded together as one high signal
 * Added: Incident Response | Re-checks the site after a response runs and lists
   what is still open
 * Added: Overview | Notes when failed sign-ins or the scheduler’s timing are far
   outside this site’s last 30 days
 * Added: AI Explanations | Explain my audit summarizes the open findings in three
   short paragraphs that cite each finding
 * Added: Settings Import | Bring over protections and sign-in attempt limits from
   another security plugin, with a preview and an undo
 * Added: MCP Server | Connect Claude, ChatGPT or any MCP assistant to read the 
   audit, activity and file check, apply fixes you can undo and restore changed 
   files, with every call logged
 * Added: Agents | A new Agents section with Connect, Requests, Permissions and 
   Surface tabs
 * Added: BetterShield Hub | Optional hub connection from BetterShield > Hub, Settings
   or the end of Quick Setup, approved once on the site’s own consent page
 * Added: Overview | A storage card that names a missing database table or column
   and offers a Repair
 * Added: Uninstall | A third choice when deleting the plugin: pack the quarantined
   copies into one archive, then remove them
 * Added: Hardening | A sixteenth fix: refuse new passwords found in known breaches,
   off by default
 * Added: File Integrity | Reports a new .user.ini file that appears after the site’s
   configuration was recorded
 * Added: Security Audit | Names PHP files and folders in the plugins folder that
   no installed plugin claims
 * Added: Security Audit | Flags directory plugins with no update for two years,
   with the last-updated date
 * Added: Form Protection | Comment bursts are held for moderation, and repeated
   password resets and sign-ups from one connection are paused
 * Added: WooCommerce | Customers manage two-factor, passkeys and signed-in devices
   from a Sign-in security tab on My Account
 * Added: Login Protection | Block a username from signing in
 * Added: Security Audit | Finds installer and database tools left in the web root,
   with quarantine from the finding
 * Added: Security Audit | Checks whether admin-ajax shares signed-in answers with
   other websites, and names where the policy was widened
 * Added: Security Audit | Detects a sign-in page served by a page cache or CDN
 * Added: Security Audit | Checks the domain’s SPF, DMARC and CAA records once a
   day
 * Added: Security Audit | Warns when free disk space runs low
 * Added: Findings | Snooze a finding for 7 or 30 days, with its own Snoozed filter
   and `wp bettershield findings --status=snoozed`
 * Added: Plugins Screen | Add New shows whether a plugin is closed on WordPress.
   org or has had no update for two years
 * Added: Application Passwords | Limit an application password to its REST routes,
   its network, or both, from Agents > Surface
 * Added: Site Moves | When the site address or folder changes, the Overview asks
   whether it is a staging copy or a move, with one undo
 * Added: Incident Response | Ask a privileged account for a new password, with 
   an undo
 * Improved: Quick Setup | Previews what each fix will do before applying it, leaves
   risky fixes unticked, and undoes the applied set in one step
 * Improved: Request Protection | Each public form has its own threshold, window
   and closing time, with a replay of the last two days before you save
 * Improved: Incidents | Evidence names each row’s network and links to the activity
   log for the incident’s days
 * Improved: Activity Log | Open everything from one person or one network from 
   any log row, and narrow agent activity to one account
 * Improved: Multisite | The network overview shows how many sites it lists and 
   loads more on request on networks of more than 200 sites
 * Improved: Privacy | Add-ons can declare a per-site personal data record so the
   privacy export finds it
 * Improved: Audit | Says how many checks could be evaluated when a run could not
   check them all, and marks findings kept from an earlier run
 * Improved: File Integrity | A changed file too long to compare whole shows the
   part that changed
 * Improved: File Integrity | A plugin copy you reviewed and adopted stays quiet
   until it changes again
 * Improved: Login Protection | Repeat lockouts within a day double in length, up
   to one day
 * Improved: Compatibility | Recognizes one more security plugin, so the same job
   is not done twice
 * Improved: Settings Import | Brings over sign-in attempt limits, allowed addresses,
   the breached-password check, username discovery block, version hiding and uploads
   protection from one more security plugin
 * Improved: Settings Export | Blocked usernames are included in an exported settings
   file
 * Improved: File Integrity | The Files screen groups changes by plugin and version,
   with Check again and Mark all expected (`wp bettershield integrity recheck` and`
   expect`)
 * Improved: Activity Log | Notes which code files an update to a plugin outside
   the directory added or changed
 * Improved: Alerts | Connecting an assistant, rotating its credential or approving
   an app sends an instant alert
 * Improved: Hardening | The usage preview on the XML-RPC and application password
   fixes looks back across the whole activity record
 * Improved: Admin Menu | The sidebar shows the BetterShield icon
 * Improved: Confirmations | Applying an incident response, disabling the decoy 
   URL and withdrawing an agent’s confirmation ask once more before acting
 * Improved: Agents | A credential connected while agents may not change the site
   is issued read-only
 * Fixed: Login Protection | Sign-in lockouts keep working right after an update,
   before the database is upgraded
 * Fixed: Login Protection | Lockouts stand down behind a proxy that forwards no
   visitor address, instead of locking all visitors out together
 * Fixed: Multisite | On installs with more than one network, the network dashboard
   and activity log show only that network’s sites
 * Fixed: Hardening | A protection set to applied while safe mode is on is shown
   as paused
 * Fixed: WP-CLI | The agent-activity export carries every matching row, or says
   where it stopped

#### 1.0.0 – 13/09/2026

 * First public release
 * Added: Security Audit | 40 read-only checks, a score that shows its workings 
   and a plain-language explanation of every finding
 * Added: Hardening | 15 one-click fixes, each showing what it will change first,
   each with an undo that never expires
 * Added: Two-Factor Authentication | Any authenticator app, 10 single-use backup
   codes, and passkeys
 * Added: Login Protection | Lockouts after repeated wrong passwords, an allowlist
   and a blocklist, session limits and an optional idle timeout
 * Added: Recovery | A recovery link, safe mode and printed offline codes, with 
   daily readiness checks and optional weekly email tests
 * Added: Activity Log | Sign-ins, accounts, roles, plugins, themes and the plugin’s
   own actions, with filters, search, CSV export and a daily seal
 * Added: File Integrity | Core and directory-plugin files compared with the copies
   WordPress.org publishes, with the difference shown and one click to restore a
   file
 * Added: Alerts | A weekly email summary that arrives on quiet weeks too, and high
   and critical events sent on their own
 * Added: Tools | WP-CLI commands, settings export and import, findings in Site 
   Health, a dashboard widget, and a report of what connected agents can do
 * Added: Multisite | Every site’s score in one table and rules a network can set
   once

## Мета

 *  Издање **1.1.0**
 *  Последње ажурирање **пре 3 дана**
 *  Активних постављања **Мање од 10**
 *  Издање Вордпреса ** 6.7 или новије **
 *  Испробано до **7.1.3**
 *  PHP издање ** 8.0 или новије **
 *  Језик
 * [English (US)](https://wordpress.org/plugins/bettershield/)
 * Ознаке
 * [2FA](https://sr.wordpress.org/plugins/tags/2fa/)[Activity Log](https://sr.wordpress.org/plugins/tags/activity-log/)
   [hardening](https://sr.wordpress.org/plugins/tags/hardening/)[login security](https://sr.wordpress.org/plugins/tags/login-security/)
   [security](https://sr.wordpress.org/plugins/tags/security/)
 *  [Напредни преглед](https://sr.wordpress.org/plugins/bettershield/advanced/)

## Оцене

Још нису послате рецензије.

[Ваша рецензија](https://wordpress.org/support/plugin/bettershield/reviews/#new-post)

[Види све рецензије](https://wordpress.org/support/plugin/bettershield/reviews/)

## Сарадници

 *   [ WPDeveloper ](https://profiles.wordpress.org/wpdevteam/)

## Подршка

Имате нешто да кажете? Потребна вам је помоћ?

 [Види форум подршке](https://wordpress.org/support/plugin/bettershield/)