Security

Hardening wp-config.php: Security Settings Every WordPress Site Should Use

Security settings in wp-config.php explained: security keys, disabling file editing, debug settings, forcing SSL for admin, file permissions and protecting the file itself, with cautions for each.

Hardening wp-config.php: Security Settings Every WordPress Site Should Use
On this page
  1. 1. Unique security keys and salts
  2. 2. Disable file editing in the dashboard
  3. 3. Turn off debug display on live sites
  4. 4. Force HTTPS for the admin area
  5. 5. Strong database credentials
  6. 6. Protect the file itself
  7. 7. Automatic updates
  8. Check it after a hack
  9. Not comfortable editing it?
Key takeaways
  • Use unique security keys, and change them after a hack to log everyone out.
  • Disable dashboard file editing, keep debug display off and force SSL for admin.
  • Protect the file with strict permissions and check it for injected code after a hack.

wp-config.php holds your WordPress database credentials and core settings, which makes it one of the most sensitive files on your site. A few settings in this file noticeably improve security. Always back up the file before editing, since a typo can take the site down.

1. Unique security keys and salts

These random strings secure login cookies. They should be unique and long. WordPress.org provides a generator for fresh keys. Changing them logs everyone out, which is useful after a hack.

2. Disable file editing in the dashboard

Setting DISALLOW_FILE_EDIT to true removes the theme and plugin code editors from the dashboard. If an attacker gets into an admin account, they can't easily edit PHP files from there.

A stricter setting, DISALLOW_FILE_MODS, also blocks installing and updating plugins from the dashboard. Only use it if updates are handled another way.

3. Turn off debug display on live sites

Debug output can reveal file paths and other details to visitors. On a live site, keep debug display off. If you need to troubleshoot, log errors to a private file instead of showing them.

4. Force HTTPS for the admin area

FORCE_SSL_ADMIN ensures logins and admin sessions always use HTTPS. Your whole site should be on HTTPS anyway; see SSL errors.

5. Strong database credentials

Use a unique database user with a strong password for each site, with only the permissions WordPress needs.

6. Protect the file itself

  • Set stricter file permissions; see file permissions explained
  • Block web access to it with a server rule
  • WordPress also looks for wp-config.php one folder above the site root, which some setups use for extra protection

7. Automatic updates

WordPress applies minor core security releases automatically by default. Keep this enabled unless your update process covers it.

Check it after a hack

Attackers often inject code at the very top or bottom of wp-config.php. Compare it with a clean copy during clean-up; see finding backdoors.

Not comfortable editing it?

A developer can apply these settings safely as part of hardening; see malware removal and security hardening or WordPress maintenance.

Need help with your website?

I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.

Found this useful? Share it:
Contact

Let's build your next website

Available for freelance projects, agency white-label work and long-term maintenance. Feel free to pass this along to your team or company.

Your details are emailed to me, then WhatsApp opens so we can chat right away.

Chat now