What is wp-config.php?
WordPress is a popular tool for building websites. The file wp-config.php holds your database name, user name and password. The database is where your posts and settings are stored. If a hacker reads this file, they can reach your data. Normally the server hides its contents. This extra rule adds a second lock.
The file .htaccess holds extra rules for the Apache web server. This tip works on Apache or similar servers. If your site runs on another server type, ask Hostvento support.
Warning
A wrong rule in .htaccess can break your whole site. Take a backup of the file before you edit it.
Steps
- Log in to cPanel.
- Click File Manager.
- Open the
public_htmlfolder, or the folder where WordPress is installed. - Click Settings at the top right and tick Show Hidden Files (dotfiles). Click Save.
- Right-click
.htaccessand choose Copy to make a backup. Name the copy.htaccess-backup. - Right-click
.htaccessand choose Edit. - Add this block at the very top or bottom of the file:
This tells the server to refuse every request for that file.<files wp-config.php> order allow,deny deny from all </files> - Click Save Changes.
- Open your website to check that it still works.
- Try to open
yourdomain.com/wp-config.php. You should see a "403 Forbidden" error, or a blank page.
On newer Apache 2.4 servers you can use this form instead:
<Files wp-config.php>
Require all denied
</Files>
Use only one of the two forms, not both.
Other good ideas
- Set the file permissions of
wp-config.phpto 600 or 640. Right-click the file in File Manager and choose Change Permissions. - Move the file one folder above your site folder. WordPress still finds it there.
.htaccess at once.Quick recap
- wp-config.php holds your database password.
- Back up
.htaccessfirst. - Add a rule that denies all access to the file.
- Test your site and the file address.