Wordpress

5 Essential Security Hardening Hacks for WordPress via .htaccess & wp-config.php

5 min read
5 Essential Security Hardening Hacks for WordPress via .htaccess & wp-config.php

Why .htaccess and wp-config.php Are Your First Line of Defense

Most WordPress security plugins are really just wrappers around a handful of server-level rules — rules you can write yourself in two files that already exist on every install: .htaccess and wp-config.php. Editing these directly means one less plugin eating your memory limit, and rules that apply before WordPress even finishes loading.

Back up both files before you touch them. A single misplaced character in .htaccess can throw a 500 error, and you'll want the original to roll back to.

1. Disable the Built-In File Editor

By default, any user with Administrator access can edit theme and plugin PHP files directly from the WordPress dashboard under Appearance → Theme Editor. If an attacker ever compromises an admin login, this editor becomes a one-click way to inject a backdoor into your site without ever touching FTP or SSH.

Where to insert: wp-config.php, right above the line that reads /* That's all, stop editing! Happy publishing. */

  1. Connect to your site via FTP, SFTP, or your hosting file manager.
  2. Open wp-config.php in a plain text editor.
  3. Paste the snippet below just before the "stop editing" comment line.
  4. Save the file and reload your dashboard — Theme Editor and Plugin Editor should disappear from the menu.
define('DISALLOW_FILE_EDIT', true);

2. Lock Down wp-config.php Itself

wp-config.php holds your database name, username, password, and secret authentication keys — everything an attacker needs to fully compromise your site if they can read this one file. A misconfigured server can sometimes serve PHP files as plain text, exposing all of it.

Where to insert: your site's root .htaccess file (the same directory as wp-config.php).

  1. Open .htaccess in your file manager or FTP client.
  2. Add the snippet below anywhere outside the # BEGIN WordPress / # END WordPress block, so WordPress core updates don't overwrite it.
  3. Save and try visiting yoursite.com/wp-config.php directly in a browser — you should get a 403 Forbidden error.
<Files wp-config.php>
Order Allow,Deny
Deny from all
</Files>

3. Turn Off Directory Browsing

If a folder on your server has no index.php file and directory browsing is enabled, anyone can visit that folder's URL and see a full file listing — theme files, plugin files, even backup archives you forgot to delete. This is a common first step attackers use for reconnaissance before an actual attack.

Where to insert: your site's root .htaccess file.

  1. Open .htaccess.
  2. Add the single line below, again outside the WordPress core block.
  3. Save, then test by visiting a known folder URL like yoursite.com/wp-content/uploads/ — it should return a 403 error instead of a file list.
Options -Indexes

4. Block XML-RPC Attacks

xmlrpc.php was built to let external apps (like the old WordPress mobile app) talk to your site remotely, but it's now mostly known for two things: brute-force login attempts that bypass normal login lockout tools, and pingback-based DDoS amplification attacks against other sites. Unless you specifically use the Jetpack plugin or a mobile app that depends on it, you can safely block it entirely.

Where to insert: your site's root .htaccess file.

  1. Open .htaccess.
  2. Add the snippet below outside the WordPress core block.
  3. Save and confirm by visiting yoursite.com/xmlrpc.php — you should see a 403 Forbidden response instead of the "XML-RPC server accepts POST requests only" message.
<Files xmlrpc.php>
Order Allow,Deny
Deny from all
</Files>

5. Stop PHP Execution Inside the Uploads Folder

The /wp-content/uploads/ folder is meant for images, PDFs, and media — never PHP code. But it's also one of the most common places attackers try to drop a malicious PHP file (a "web shell") after exploiting a vulnerable plugin or a weak upload form, since this folder is almost always writable. Blocking PHP execution here neutralizes that entire attack path, even if a bad file does slip through.

Where to insert: a new .htaccess file inside /wp-content/uploads/ — do not add this to your root .htaccess, or it will block your entire site's PHP.

  1. Navigate to /wp-content/uploads/ in your file manager or FTP client.
  2. Create a new file named exactly .htaccess if one doesn't already exist there.
  3. Paste the snippet below into it and save.
  4. Test by uploading a harmless test.php file into that folder and visiting its URL directly — it should return a 403 error instead of executing.
<Files *.php>
Order Deny,Allow
Deny from all
</Files>

Final Checklist

  • Backed up wp-config.php and both .htaccess files before editing.
  • Added DISALLOW_FILE_EDIT to wp-config.php and confirmed the Theme/Plugin Editor menus are gone.
  • Blocked direct access to wp-config.php and confirmed a 403 error on load.
  • Disabled directory browsing and confirmed folder listings return a 403 error.
  • Blocked xmlrpc.php, unless you actively rely on Jetpack or a legacy mobile app.
  • Added a separate .htaccess inside /wp-content/uploads/ to block PHP execution.

None of these five changes require a plugin, none of them touch your database, and all of them can be undone in seconds by restoring the backups you made in step one. Apply them one at a time and reload your site after each change — that way, if something breaks, you know exactly which line caused it.

You May Also Like

Related Articles

Comments & Feature Requests

0 Found a bug, or want a new tool? Let us know below.

Comments are reviewed before appearing publicly.

comments_no_comments