
YuraCode Security makes your site safer as soon as you activate it. Nothing to configure: every protection is already on with safe, recommended settings. There are no external calls and no dashboard to manage. Review or adjust anything on the Settings YuraCode Security screen.
It protects your site in three ways: hardening, login protection, and a firewall.
Hardening
- Hides your site’s version – attackers scan for known bugs in WordPress, so showing your version makes you an easier target.
- Closes a little-used door that attackers abuse.
- Locks down the file editor – stops plugins and themes being edited from the admin, so a hacked admin account can’t plant backdoors.
- Generic login errors – the same message for any wrong password, so attackers can’t confirm a username.
- Removes the extra code WordPress loads for emojis – trims a little weight from every page.
- Stops your site pinging itself – no more self-pings when you link to your own posts.
- Blocks an extra way for external tools to get into your site.
- Stops WordPress and plugins from running AI prompts on your site.
- Disable comments – ends comment spam and hides existing comments. Off by default because blogs use comments; turn it on if your site doesn’t (most don’t).
Login Protection
- Stops attackers hammering your login form with password guesses. After too many failed attempts from the same address, that address is locked out for a while (5 attempts by default, for 15 minutes). Both are adjustable.
Firewall
A firewall that watches every visit before your site even loads and rejects the requests that don’t look right. Your sensitive files are protected from being downloaded, and uploaded files can’t run code on your server.
- Blocks known attack patterns – malicious requests and suspicious visitors are rejected at the door.
- Protects your sensitive files – your site’s configuration and backup files can’t be downloaded.
- Blocks dangerous uploads – files uploaded to your site can’t run code.
Privacy
YuraCode Security makes no external requests and collects no user data. It runs entirely on your server. The only files it writes are its own settings and the firewall rules it manages, with a backup of your original file kept in the uploads folder. Nothing is sent anywhere.
Credits
The built-in firewall ruleset is the 8G Firewall by Jeff Starr (Perishable Press), bundled under the GPL.
Screenshots

The settings screen: every protection is already on with recommended settings.

Login protection: attackers are locked out after too many failed attempts.

The firewall: malicious traffic is blocked before it reaches your site.