Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Protect the Source Code of Your Website

This guide explains what you can and cannot hide in your website code, and how to keep the private parts safe.

How-To Guides2 min read8 steps

What is source code?

Source code is the set of instructions that builds your website. Some of it runs on the server, such as PHP. Some of it is sent to the visitor's browser, such as HTML, CSS and JavaScript. Think of a restaurant. The kitchen is the server. The plate is what the browser receives.

The honest truth

You cannot hide code that is sent to the browser. If a browser can read it, a person can read it too. Tricks like blocking right-click do not work. Anyone can still open the page source. So the goal is different. Keep your secrets on the server, and make the visible code hard to copy in bulk.

Steps

  1. Keep secrets out of browser code. Never put passwords, API keys or database details in JavaScript or HTML. An API key is a secret code that lets a program use a service.
  2. Keep private logic in PHP or another server language. Visitors never see server code. They see only its output.
  3. Stop people from browsing your folders. Add this line to a file named .htaccess in your website folder.
    Options -Indexes
    This turns off folder listings on Apache servers.
  4. Block sensitive files. Add this to .htaccess to deny access to files like config backups.
    <FilesMatch "\.(env|log|sql|bak)$">
    Require all denied
    </FilesMatch>
  5. Move private files above the web folder. Files outside public_html cannot be opened from a web address.
  6. Minify your JavaScript. Minify means squeezing code into a short, hard-to-read form. It does not make code secret. It only makes it harder to read.
  7. Add a license. A license notice states that others may not copy your work. It gives you legal protection.
  8. Keep software updated and use strong passwords. Most leaks come from hacked accounts, not from page source.
Tip: Take a backup before you edit .htaccess. A small typo can show an error page on your whole site.

If you need stronger protection for your account, ask Hostvento support what options your plan has.

Quick recap

  • Code sent to the browser can always be seen.
  • Keep passwords and keys on the server only.
  • Turn off folder listing and block sensitive files.
  • Use updates and strong passwords to stay safe.