I particularly like the "hide backend feature" - any hacker who wants to try getting in through **/wp-admin first has to guess the custom address you've given your admin pages... he gets a 404 and if he tries too often he is banned !
The file change warning does have hiccups - you need to check exclusions and, at the moment Better security send one, blank, email before sending one that contains the information.