Skip to content

Instantly share code, notes, and snippets.

@jennimckinnon
Created May 18, 2016 22:25
Show Gist options
  • Select an option

  • Save jennimckinnon/c1696c5f022e7aadca886716e69f9c99 to your computer and use it in GitHub Desktop.

Select an option

Save jennimckinnon/c1696c5f022e7aadca886716e69f9c99 to your computer and use it in GitHub Desktop.
Protect error logs, wp-config.php, php.ini and .htaccess for WordPress sites.
<FilesMatch "^.*(error_log|wp-config\.php|php.ini|\.[hH][tT][aApP].*)$">
Order deny,allow
Deny from all
</FilesMatch>
@dhgutteridge

Copy link
Copy Markdown

Here, strictly speaking you should escape the period in "php.ini" ("php.ini"), and if unsure whether it has a number in it (php5.ini, php7.ini, whatever), you could simply use "php.?.ini" instead.

@dhgutteridge

Copy link
Copy Markdown

Argh, I didn't escape the backslashes, I meant "php\.ini" or "php.?\.ini".

@jennimckinnon

Copy link
Copy Markdown
Author

This example was taken from the WP Codex so suggestions should be made there, to this doc: https://codex.wordpress.org/htaccess

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment