Account Security, 2FA & Active Sessions
Updated 1 September 2026
Your BugShield account can contain site access, conversations and operational history, so securing the account is as important as securing WordPress itself. Read Vault Security & Access for guidance about protecting stored site credentials.
Update your password
Open Settings > Login & Security to change your password. Use a unique password that is not shared with WordPress, hosting, email or another service.
Enable two-factor authentication
- Open the Two-factor (2FA) section in Login & Security.
- Start setup and scan the QR code with an authenticator app such as Google Authenticator, Authy or 1Password.
- Enter the current six-digit code to confirm setup.
- On the Save your backup codes screen, select Download and store the file somewhere safe.
After 2FA is enabled, sign-in requires your password and an authenticator or backup code. Each backup code can only be used once. Download them from the Save your backup codes screen before selecting Done.
Review active sessions
The Active sessions list shows devices signed in to your account, their approximate location and when they were last active. Your current device is clearly labelled to help you review the list. You can select Sign out for an older or unfamiliar session to securely end its access to your account.
If you notice suspicious access
- Change your BugShield password immediately.
- Sign out unfamiliar active sessions.
- Enable 2FA if it is not already active.
- Review Vault items and activity records for unexpected changes or access.
- Contact BugShield if you need help securing the account.
Common questions
Frequently Asked Questions
Which authenticator apps can I use?
Any standard time-based authenticator app should work, including Google Authenticator, Authy and 1Password.
What are 2FA backup codes for?
They let you sign in if your authenticator is unavailable. Each code works once, so store them securely away from your normal login device.
Can I sign another device out remotely?
Yes. Open Active sessions in Login & Security and choose Sign out for the device.
Are session locations exact?
No. Device locations are approximate and are intended as an account-security signal rather than precise tracking.