Connect with us

WordPress: How to Block PHP Execution by Directory?


WordPress: How to Block PHP Execution by Directory?

We’ve seen numerous WordPress installations that have been hacked where the hackers have uploaded secret files into the wp-content and wp-includes folders that are named similarly to actual WordPress filenames, but are actually shell, malware or even mailer scripts which allow the hackers the use of your hosting account for their own devices.  These PHP scripts can wreak havoc on the server environment, get your IP blacklisted and force server admins to take your site down.  Here’s one tip we recommend to help prevent this from happening.

In order to block hackers from executing PHP scripts in these directories you can create an .htaccess file in these directories which tells the server PHP should NOT be run in them directly.  Here’s the code to place in a blank .htaccess file:

 <Files *.php>
 deny from all


You can then upload that .htaccess file to your wp-content and wp-includes folders.

Please Note: uploading this file to the wp-content folder can cause an issue with some themes and plugins, especially those using timthumb.php directly.  If that’s the case, just delete the file and all will be fixed.

Related:  Basic SEO – Do It Youselfer (DIY) Using Some Basic PHP Code
Continue Reading
You may also like...

We are a WordPress plugin developer company that focuses on useful WordPress plugin creation and empowering people to earn passive incomes from their blogs. We build unique and groundbreaking plugins that will revolutionize your blog!

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

More in solution

    Sign up for our newsletter and get a free affiliate e-book!

    About Me:

    Szabi Kisded

    Hi, my name is Szabi and I'm documenting my journey selling plugins on CodeCanyon. I will show you every step of it: learning to code, plugin ideas, WordPress stuff and more. Read more…

    Mega Plugin Bundle:

    CodeCanyon Portfolio:

    Online Courses:

    Latest Promotions:

    Recommended Theme:

    Start Your Own Blog:

    Translate Your Blog:

    AdSense Alternative:

    Best Article Spinner:

    Popular Posts:

    Latest Posts:

    To Top

    Privacy Preference Center