Title: YuraCode Security
Author: yuracode
Published: <strong>2026 年 9 月 14 日</strong>
Last modified: 2026 年 9 月 26 日

---

搜尋外掛

![](https://ps.w.org/yuracode-security/assets/banner-772x250.png?rev=3703419)

![](https://ps.w.org/yuracode-security/assets/icon-256x256.png?rev=3696012)

# YuraCode Security

 由 [yuracode](https://profiles.wordpress.org/yuracode/) 開發

[下載](https://downloads.wordpress.org/plugin/yuracode-security.1.0.5.zip)

 * [詳細資料](https://tw.wordpress.org/plugins/yuracode-security/#description)
 * [使用者評論](https://tw.wordpress.org/plugins/yuracode-security/#reviews)
 *  [安裝方式](https://tw.wordpress.org/plugins/yuracode-security/#installation)
 * [開發資訊](https://tw.wordpress.org/plugins/yuracode-security/#developers)

 [技術支援](https://wordpress.org/support/plugin/yuracode-security/)

## 外掛說明

YuraCode Security helps keep your WordPress site safe from the moment you activate
it. There’s nothing to set up. Every protection is already on with safe, recommended
settings. You can review or change anything on the Settings  YuraCode Security screen.

We protect your site in three simple ways: **Closing Security Loopholes**, **Stopping
Password Guessers**, and **Filtering Bad Traffic**.

#### 1. Closing Security Loopholes

 * **Hides your WordPress version:** Attackers scan for specific WordPress versions
   with known bugs. We hide yours so you’re not an easy target.
 * **Locks down the file editor:** Intruders often use the built-in editor to plant
   malicious code. We turn it off so a compromised account can’t ruin your site.
 * **Doesn’t reveal usernames:** Shows the same generic error whether the username
   or the password is wrong, so attackers can’t tell which accounts are real.
 * **Turns off risky features:** We switch off little-used features that attackers
   often abuse to get in, like XML-RPC and application passwords.
 * **Blocks AI requests:** Turns off WordPress’s AI client so plugins and core can’t
   send prompts out from your site.
 * **Adds browser protection:** Tells visitors’ browsers to be stricter with your
   pages, which blocks a few common disguise tricks and stops other sites from pretending
   to be you.
 * **Optional spam protection:** Turn off comments entirely to stop comment spam
   bots (off by default).

#### 2. Stopping Password Guessers

 * **Blocks “Brute Force” attacks:** Attackers use automated bots to guess thousands
   of passwords a second. YuraCode watches your login form and instantly locks out
   anyone who guesses wrong too many times (default: 5 failed attempts locks them
   out for 15 minutes).

#### 3. Filtering Bad Traffic (Firewall)

Think of this as a bouncer at the door of your website. It checks every visitor 
before your site even loads and kicks out the troublemakers.
 * **Blocks malicious
visitors:** Recognizes known attack patterns and blocks them immediately. * **Protects
your private files:** Ensures sensitive files (like your site’s database settings
or backups) can’t be downloaded by strangers. * **Stops malicious uploads:** If 
an attacker manages to upload a file, this prevents the file from actually running
any harmful code on your server.

### Privacy

YuraCode Security makes no external requests and collects zero user data. It runs
entirely on your server. The only files it writes are its own local settings and
the firewall rules it manages (with an automatic backup of your original file kept
in the uploads folder).

### Credits

The built-in firewall ruleset is the excellent [8G Firewall](https://perishablepress.com/8g-firewall/)
by Perishable Press.

## 螢幕擷圖

[⌊The settings screen: every protection is already on with recommended settings.⌉⌊
The settings screen: every protection is already on with recommended settings.⌉[

The settings screen: every protection is already on with recommended settings.

[⌊Login protection: attackers are locked out after too many failed attempts.⌉⌊Login
protection: attackers are locked out after too many failed attempts.⌉[

Login protection: attackers are locked out after too many failed attempts.

[⌊The firewall: malicious traffic is blocked before it reaches your site.⌉⌊The firewall:
malicious traffic is blocked before it reaches your site.⌉[

The firewall: malicious traffic is blocked before it reaches your site.

## 安裝方式

 1. Install and activate YuraCode Security from your site’s **Plugins** screen.
 2. Done! Your site is instantly protected.
 3. (Optional) If you ever need to change a setting, you can review them on the **Settings
    YuraCode Security** screen.

## 常見問題集

### Do I need to configure anything?

No. Every protection is already turned on with safe, recommended settings. You can
review or adjust them at any time under **Settings  YuraCode Security**.

### Does YuraCode Security work on any hosting?

Yes! The core protections (closing loopholes and stopping password guessers) work
on every hosting setup. The firewall feature requires an Apache or LiteSpeed server(
which most shared hosting uses). If your site runs on nginx or IIS, the plugin detects
that and skips the firewall, with a notice explaining why.

### Does YuraCode Security speed up my site?

It is not a caching or optimization plugin, but it does trim a little: emojis and
self-pinging add background code to every page, and we remove it. The effect is 
modest; the main benefit is security.

### Does YuraCode Security send my data anywhere?

Never. The plugin runs 100% on your server, makes no external calls, and collects
zero data. Your privacy is fully protected.

### What happens to my site when I deactivate the plugin?

Everything goes right back to normal. The firewall’s rules are safely removed from
your `.htaccess` file, and a backup of your original file is kept in your uploads
folder just in case.

### I am a developer. What exactly does it do technically?

 * Disables XML-RPC, theme and plugin file editors, application passwords, AI prompts,
   emojis, and self-pingbacks.
 * Hides the WordPress core and asset version strings, and returns generic login
   error messages.
 * Sends conservative response headers on the front end: `X-Content-Type-Options:
   nosniff`, `Referrer-Policy: strict-origin-when-cross-origin`, and `X-Frame-Options:
   SAMEORIGIN`. Each is only sent when nothing else has already set it.
 * Login protection throttles an IP address after too many failed attempts.
 * The firewall uses the 8G ruleset by Perishable Press, written to `.htaccess` 
   and the uploads folder, to block malicious query strings, request URIs, user 
   agents, and referrers. It also protects `wp-config.php` and blocks PHP execution
   in `/uploads`.

## 使用者評論

這個外掛目前沒有任何使用者評論。

## 參與者及開發者

以下人員參與了開源軟體〈YuraCode Security〉的開發相關工作。

參與者

 *   [ yuracode ](https://profiles.wordpress.org/yuracode/)

[將〈YuraCode Security〉外掛本地化為台灣繁體中文版](https://translate.wordpress.org/projects/wp-plugins/yuracode-security)

### 對開發相關資訊感興趣？

任何人均可[瀏覽程式碼](https://plugins.trac.wordpress.org/browser/yuracode-security/)、
查看 [SVN 存放庫](https://plugins.svn.wordpress.org/yuracode-security/)，或透過 
[RSS](https://plugins.trac.wordpress.org/log/yuracode-security/?limit=100&mode=stop_on_copy&format=rss)
訂閱[開發記錄](https://plugins.trac.wordpress.org/log/yuracode-security/)。

## 變更記錄

#### 1.0.5

 * Improved the settings screen: dependent options grey out with their switch, saving
   keeps the current tab, and a warning appears when the WordPress permalink rules
   are missing.

#### 1.0.4

 * New: Validates template paths so a page cannot load a template from outside your
   theme.
 * New: Restricts the REST batch API to users who can edit content.
 * New: Adds an option to keep every plugin and theme on its latest version automatically.

#### 1.0.3

 * New: A dismissible prompt on the settings screen to enable automatic plugin updates.

#### 1.0.2

 * New: Sends safer browser response headers (file-type sniffing, referrer, and 
   clickjacking protection).
 * Fixed: The firewall’s local-development detection now also works when the rules
   are generated from the command line or a scheduled task, so it no longer blocks
   the login page on a localhost site.

#### 1.0.1

 * New: Turn off the built-in theme and plugin file editor.
 * Fixed: the firewall no longer gets in the way on local development sites (localhost/
   loopback).

#### 1.0.0

 * Initial release.

## 中繼資料

 *  版本 **1.0.5**
 *  最後更新 **5 天前**
 *  啟用安裝數 **少於 10 次**
 *  WordPress 版本需求 ** 6.0 或更新版本 **
 *  已測試相容的 WordPress 版本 **7.1.2**
 *  PHP 版本需求 ** 8.0 或更新版本 **
 *  語言
 * [English (US)](https://wordpress.org/plugins/yuracode-security/)
 * 標籤:
 * [firewall](https://tw.wordpress.org/plugins/tags/firewall/)[login](https://tw.wordpress.org/plugins/tags/login/)
   [malware](https://tw.wordpress.org/plugins/tags/malware/)[security](https://tw.wordpress.org/plugins/tags/security/)
   [spam](https://tw.wordpress.org/plugins/tags/spam/)
 *  [進階檢視](https://tw.wordpress.org/plugins/yuracode-security/advanced/)

## 評分

這個項目尚無任何評論記錄。

[撰寫評分](https://wordpress.org/support/plugin/yuracode-security/reviews/#new-post)

[查看全部使用者評論](https://wordpress.org/support/plugin/yuracode-security/reviews/)

## 參與者

 *   [ yuracode ](https://profiles.wordpress.org/yuracode/)

## 技術支援

使用者可在技術支援論壇提出意見反應或使用問題。

 [檢視技術支援論壇](https://wordpress.org/support/plugin/yuracode-security/)