Plugin

Protect wp-config.php · Block Direct Browser Access to Config Files

Returns a blank page if anyone loads wp-config.php or common backup filenames directly in a browser — lightweight, zero configuration.

Version
15.01
Price
Free

Returns a blank page if anyone tries to load wp-config.php or common backup filenames directly in a browser.

What you get

  • Latest stable plugin ZIP from WordPress.org
  • Public source on GitHub for review and contribution
  • GPL v2-licensed code, free for personal and commercial use

Install

  1. Download the ZIP and upload via Plugins → add New → Upload Plugin.
  2. activate from the Plugins screen.
  3. No configuration required.

Source code

The full source lives on GitHub at https://github.com/thisismyurl/protect-wp-config-from-phishing-attacks. Issues and pull requests welcome.

WordPress.org listing

Originally published at https://wordpress.org/shipped/protect-wp-config-from-phishing-attacks/.

Other downloads from this practice