Connect with us

WordPress: How to Block PHP Execution by Directory?


WordPress: How to Block PHP Execution by Directory?

We’ve seen numerous WordPress installations that have been hacked where the hackers have uploaded secret files into the wp-content and wp-includes folders that are named similarly to actual WordPress filenames, but are actually shell, malware or even mailer scripts which allow the hackers the use of your hosting account for their own devices.  These PHP scripts can wreak havoc on the server environment, get your IP blacklisted and force server admins to take your site down.  Here’s one tip we recommend to help prevent this from happening.

In order to block hackers from executing PHP scripts in these directories you can create an .htaccess file in these directories which tells the server PHP should NOT be run in them directly.  Here’s the code to place in a blank .htaccess file:

 <Files *.php>
 deny from all


You can then upload that .htaccess file to your wp-content and wp-includes folders.

Please Note: uploading this file to the wp-content folder can cause an issue with some themes and plugins, especially those using timthumb.php directly.  If that’s the case, just delete the file and all will be fixed.

Related:  Responsive Restaurant WordPress Themes
Continue Reading
You may also like...

We are a WordPress plugin developer company that focuses on useful WordPress plugin creation and empowering people to earn passive incomes from their blogs. We build unique and groundbreaking plugins that will revolutionize your blog!

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

More in solution

    Sign up for our newsletter and get a free affiliate e-book!

    About Me:

    Szabi Kisded

    Hi, my name is Szabi and I'm documenting my journey earning an online (semi)passive income. Learn more

    Mega Plugin Bundle:

    CodeCanyon Portfolio:

    Online Courses:

    Recommended Theme:

    Popular Posts:

    Latest Posts:

    To Top