WordPress

How to Block access to WordPress files that reveal version information

For extra security we recommend blocking access to the WordPress readme.html file and other default WordPress files which publicly display your current WordPress version number.

Rather than deleting these files, it’s better to add the following directive to your .htaccess file to block public access to these files.


# Block access to WordPress files that reveal version information.
<filesmatch "^(wp-config\.php|readme\.html|license\.txt)">

    # Apache < 2.3
    <IfModule !mod_authz_core.c>
        Order allow,deny
        Deny from all
        Satisfy All
    </ifmodule>

    # Apache ≥ 2.3
    <ifmodule mod_authz_core.c>
        Require all denied
    </ifmodule>
</filesmatch>

Source HTML5 Boilerplate’s .htaccess for WordPress.

Was this guide helpful?

Need help with this?

Open a ticket and link to this guide so our team can see what you have tried.

View support tickets

Power your business with Ecenica Hosting

Built for WordPress and serious websites. Fast, secure and supported by real people in the UK.

Ecenica hosting services represented by a connected red route across London