Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Stop visitors from reading your .htaccess file

This guide shows how to make sure nobody can open your .htaccess file from a web browser.

Files and FTP2 min read9 steps1 screenshots

What is .htaccess?

.htaccess is a small settings file for websites on an Apache server. Apache is the program that serves web pages. This file can hold redirects, password rules and other settings. It is like a rule sheet pinned to the door of your website.

The file can contain private details. Visitors should never be able to read it. Most servers already block it by default. You can add an extra rule to be sure.

Warning: a mistake in .htaccess can take your whole site offline with a "500 Internal Server Error". Make a backup copy before you edit it.

Steps

  1. Log in to cPanel and open File Manager.
  2. Click Settings in the top right. Tick Show Hidden Files (dotfiles). Click Save. Files that start with a dot are hidden unless you do this.
  3. Open public_html.
  4. Find .htaccess. Right-click it and choose Copy to make a backup, for example .htaccess-backup.
  5. Right-click the real .htaccess and choose Edit.
  6. Go to the end of the file. Add these lines on a new line:
<Files ".htaccess">
  Require all denied
</Files>

This tells the server to refuse every web request for a file named .htaccess. Older servers use Order allow,deny and Deny from all instead. Try the first form and use the older one only if you see an error.

  1. Click Save Changes.
  2. Open your website in a browser. Check that it still loads.
  3. Type your site address followed by /.htaccess. You should see "403 Forbidden". That means access is denied.
Tip: If the site shows an error after you save, open the file again and remove the lines you added. Or rename the backup back to .htaccess.

If you cannot fix it, open a support ticket.

Quick recap

  • .htaccess holds server rules and should stay private.
  • Show hidden files in File Manager, then back up the file.
    Screenshot: Show hidden files in File Manager, then back up the file.
  • Add the deny rule and save.
  • Test the site and check that /.htaccess gives 403.