Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Deny Access to wp-config.php in WordPress

This guide shows you how to stop outsiders from reading your wp-config.php file, which holds the secrets of your WordPress site.

SSL and Security2 min read10 steps

What is wp-config.php?

WordPress is a popular tool for building websites. The file wp-config.php holds your database name, user name and password. The database is where your posts and settings are stored. If a hacker reads this file, they can reach your data. Normally the server hides its contents. This extra rule adds a second lock.

The file .htaccess holds extra rules for the Apache web server. This tip works on Apache or similar servers. If your site runs on another server type, ask Hostvento support.

Warning

A wrong rule in .htaccess can break your whole site. Take a backup of the file before you edit it.

Steps

  1. Log in to cPanel.
  2. Click File Manager.
  3. Open the public_html folder, or the folder where WordPress is installed.
  4. Click Settings at the top right and tick Show Hidden Files (dotfiles). Click Save.
  5. Right-click .htaccess and choose Copy to make a backup. Name the copy .htaccess-backup.
  6. Right-click .htaccess and choose Edit.
  7. Add this block at the very top or bottom of the file:
    <files wp-config.php>
    order allow,deny
    deny from all
    </files>
    This tells the server to refuse every request for that file.
  8. Click Save Changes.
  9. Open your website to check that it still works.
  10. Try to open yourdomain.com/wp-config.php. You should see a "403 Forbidden" error, or a blank page.

On newer Apache 2.4 servers you can use this form instead:

<Files wp-config.php>
Require all denied
</Files>

Use only one of the two forms, not both.

Other good ideas

  • Set the file permissions of wp-config.php to 600 or 640. Right-click the file in File Manager and choose Change Permissions.
  • Move the file one folder above your site folder. WordPress still finds it there.
Tip: If your site shows an error after you save, restore the backup copy of .htaccess at once.

Quick recap

  • wp-config.php holds your database password.
  • Back up .htaccess first.
  • Add a rule that denies all access to the file.
  • Test your site and the file address.