YuraCode Security protects your site the moment you activate it: no setup, no dashboard clutter, no external calls. Three focused modules cover the essentials: hardening, brute-force login protection, and an Apache-level firewall, all controlled from a single settings screen. Settings are managed on the Settings YuraCode Security screen.
?ver= query string from enqueued scripts and styles, and the shortlink and REST output links.Writes a rules block to the .htaccess file in the WordPress root (and, optionally, wp-content/uploads/.htaccess). Rules run at the Apache level, before WordPress loads. The block is kept between its own markers so it never conflicts with WordPress’s own rewrite rules, and a backup of your original file is kept in wp-content/uploads/yuracode-security/ before every change (removed on uninstall).
wp-config.php, php.ini, error_log, and .sql / .log backup files.wp-includes, wp-admin/includes, and wp-includes/theme-compat.wp-content/uploads/.htaccess that denies *.php, *.phtml, and *.phar files.All firewall rules use Apache 2.4 syntax (Require all denied). On activation the .htaccess block is written immediately; on deactivation it is removed. Servers that don’t honor .htaccess (nginx, IIS) are detected automatically and the firewall is skipped with an admin notice. If the .htaccess file is not writable, an admin notice is shown and the firewall is skipped gracefully.
YuraCode Security makes no external requests and collects no user data. It runs entirely on your server; the only files it writes are its own settings and the managed .htaccess rules (with a backup of your original kept in the uploads folder). Nothing is sent anywhere.
The built-in firewall ruleset is the 8G Firewall by Jeff Starr (Perishable Press), bundled under the GPL.