Hardening wp-config.php: Security Settings Every WordPress Site Should Use
Security settings in wp-config.php explained: security keys, disabling file editing, debug settings, forcing SSL for admin, file permissions and protecting the file itself, with cautions for each.

On this page
- Use unique security keys, and change them after a hack to log everyone out.
- Disable dashboard file editing, keep debug display off and force SSL for admin.
- Protect the file with strict permissions and check it for injected code after a hack.
wp-config.php holds your WordPress database credentials and core settings, which makes it one of the most sensitive files on your site. A few settings in this file noticeably improve security. Always back up the file before editing, since a typo can take the site down.
1. Unique security keys and salts
These random strings secure login cookies. They should be unique and long. WordPress.org provides a generator for fresh keys. Changing them logs everyone out, which is useful after a hack.
2. Disable file editing in the dashboard
Setting DISALLOW_FILE_EDIT to true removes the theme and plugin code editors from the dashboard. If an attacker gets into an admin account, they can't easily edit PHP files from there.
A stricter setting, DISALLOW_FILE_MODS, also blocks installing and updating plugins from the dashboard. Only use it if updates are handled another way.
3. Turn off debug display on live sites
Debug output can reveal file paths and other details to visitors. On a live site, keep debug display off. If you need to troubleshoot, log errors to a private file instead of showing them.
4. Force HTTPS for the admin area
FORCE_SSL_ADMIN ensures logins and admin sessions always use HTTPS. Your whole site should be on HTTPS anyway; see SSL errors.
5. Strong database credentials
Use a unique database user with a strong password for each site, with only the permissions WordPress needs.
6. Protect the file itself
- Set stricter file permissions; see file permissions explained
- Block web access to it with a server rule
- WordPress also looks for wp-config.php one folder above the site root, which some setups use for extra protection
7. Automatic updates
WordPress applies minor core security releases automatically by default. Keep this enabled unless your update process covers it.
Check it after a hack
Attackers often inject code at the very top or bottom of wp-config.php. Compare it with a clean copy during clean-up; see finding backdoors.
Not comfortable editing it?
A developer can apply these settings safely as part of hardening; see malware removal and security hardening or WordPress maintenance.
Need help with your website?
I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.


