Security starts with the BugShield account
BugShield exists so you can hand a broken site to a developer without emailing passwords into thin air. Credentials live in an encrypted vault tied to the site. Fixes are tracked. Access is logged.
None of that holds up if your BugShield login is easy to borrow. A strong password is still the foundation. What we have shipped now is a way to make that login harder to steal, without forcing every account into a heavier routine on day one.
Optional two-factor authentication
Two-factor authentication is available under Settings > Security, and it stays off until you decide otherwise. When you turn it on, you pair BugShield with an authenticator app you already trust (Google Authenticator, Authy, 1Password, or any standard TOTP app), confirm with a six-digit code, and keep a set of one-time backup codes somewhere safe for the day your phone is not nearby.
From then on, signing in means your password plus a code from the app. Lose the phone and you still have those backup codes. We deliberately skip SMS. Text messages are easier to intercept, and authenticator apps are simply the clearer standard for protecting an account that holds this much.
If you change your mind later, you can turn 2FA off again with your password and a valid code. Some people will enable it the same afternoon. Others will wait until their sites and vault are set up. Both are fine. The protection is there whenever you want it.
Active Sessions
Active Sessions is for the other half of the problem: not just how you sign in, but where you are still signed in.
Active Sessions shows the browsers and devices signed in to your account, along with their approximate location and recent activity. Your current device is clearly labelled, and you can securely sign out an older or unfamiliar session whenever needed.
Left yourself logged in on a shared laptop? You can sign out that session without needing to reset your password. Spot a login you do not recognise? Revoke it straight away, and change your password too. That second step matters. A strange session is a warning, not a full clean-up on its own.
Locations are approximate and are intended to help you recognise familiar sign-ins rather than show an exact position.
How this fits the rest of BugShield security
These updates sit with the rest of how we look after WordPress:
- An encrypted Password Vault for site credentials, with access logging
- Controlled developer access during a fix, instead of passwords floating around inboxes
- Monitoring, backups, and maintenance plans that catch problems early
- Clear activity history so you can see what happened on a site
2FA and session control tighten the front door. The vault, monitoring, and fix workflow protect what sits behind it. The idea is simple: everything that touches your website should be handled securely, starting with the BugShield account that owns it.
A small habit worth building
Next time you are in the dashboard, open Security settings. If authenticator 2FA feels right for how you work, turn it on and store the backup codes somewhere you will actually find them. While you are there, glance at Active Sessions and sign out anything that does not look like you.
If you run an agency or look after several client sites, this is especially worth doing. The more sites and credentials sit behind one login, the more that login is worth protecting.
Website security is not only plugins and scans. It is also who can open the door. We will keep hardening that door as BugShield grows. To review these options, sign in to BugShield and open Security settings.
Quick answers about BugShield account security
Is two-factor authentication required on BugShield?
No. Authenticator-based two-factor authentication is optional, and you can enable it from Settings > Security whenever you are ready.
Which type of authenticator app can I use?
You can use any authenticator app that supports standard time-based one-time passwords, often shortened to TOTP. BugShield does not rely on text-message codes.
What happens if I lose the phone used for 2FA?
Use one of the one-time backup codes created when you enabled 2FA. Keep those codes somewhere secure and separate from the device that holds your authenticator app.
What information appears under Active Sessions?
Active Sessions shows the browsers and devices currently signed into your account, when each was last active and an approximate location. Your current device is clearly labelled.
What should I do if I do not recognise a session?
Sign out that session, then change your BugShield password. The location is only an estimate, but an unfamiliar device or activity time is still worth checking.