Skip to content

Search WPDesignVault

Try "image", "json", "schema" or "contrast". Use arrow keys to move through results.

WordPress Guides

The Default WordPress .htaccess File (and Safe Additions)

If your WordPress site runs on Apache or LiteSpeed, a small file called .htaccess decides how pretty permalinks work, and it is also where many redirects, security rules and caching headers end…

On this page

If your WordPress site runs on Apache or LiteSpeed, a small file called .htaccess decides how pretty permalinks work, and it is also where many redirects, security rules and caching headers end up. A single typo in it can take the whole site offline with a 500 error. This guide shows the default file, explains every line, and lists additions that are safe and useful.

Where the file lives

.htaccess sits in the same folder as wp-config.php, usually the web root. The leading dot makes it hidden in many file managers and FTP clients, so turn on “show hidden files” if you cannot see it. Nginx servers ignore .htaccess completely; on Nginx the equivalent rules live in the server configuration, which your host manages.

The default WordPress rules

When you save Settings → Permalinks with any structure other than “Plain”, WordPress writes this block:

# BEGIN WordPress
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>
# END WordPress

What each line does

  • # BEGIN / # END WordPress: markers. WordPress rewrites everything between them whenever permalinks are saved, so never put your own rules inside.
  • IfModule mod_rewrite.c: only run the rules if the rewrite module is available, so a missing module does not cause an error.
  • RewriteEngine On: turns on URL rewriting.
  • HTTP_AUTHORIZATION: passes the Authorization header to PHP, which application passwords and some REST API clients need.
  • RewriteBase /: the base path. If WordPress is installed in a subfolder, this becomes /subfolder/.
  • ^index\.php$ – [L]: if the request is already index.php, stop.
  • The two RewriteCond lines: if the request is not a real file (-f) and not a real directory (-d)…
  • RewriteRule . /index.php [L]: …send it to index.php, where WordPress works out which post or page was requested.

Those last three lines are why images, CSS and uploads load directly while every pretty URL goes through WordPress.

Before you edit: a safety routine

  1. Download a copy of the current file and keep it.
  2. Make one change at a time.
  3. Load the home page, a post, an image and the admin area after each change.
  4. If you see “500 Internal Server Error”, restore the copy immediately, then look for the typo.

Safe, useful additions

Put your own rules above the # BEGIN WordPress line so WordPress never overwrites them and so redirects run before WordPress routing.

Force HTTPS

RewriteEngine On
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

Only add this once your SSL certificate works on every URL. Behind some load balancers or CDNs, %{HTTPS} is always off; in that case use the redirect setting in your host or CDN instead to avoid a redirect loop.

Choose www or non-www

RewriteCond %{HTTP_HOST} ^www\.(.+)$ [NC]
RewriteRule ^ https://%1%{REQUEST_URI} [L,R=301]

This sends www to the bare domain. Make sure the Site Address in Settings → General matches the version you choose.

Block access to sensitive files

<FilesMatch "^(wp-config\.php|readme\.html|license\.txt|\.htaccess)$">
  Require all denied
</FilesMatch>

Require all denied is Apache 2.4 syntax. On very old Apache 2.2 servers the equivalent is Order allow,deny / Deny from all.

Turn off directory listings

Options -Indexes

Disable PHP in the uploads folder

Create a separate .htaccess inside wp-content/uploads containing:

<FilesMatch "\.(php|phtml|phar)$">
  Require all denied
</FilesMatch>

Uploads should only ever contain media. This stops an uploaded script from running if something malicious gets in.

What not to put in .htaccess

  • Hundreds of individual redirects. Every request reads the file, so very long files slow the server. Use a redirect plugin or server config for large migrations.
  • Rules copied from old tutorials that use mod_access syntax or block whole countries by IP lists.
  • Anything inside the WordPress markers. It will disappear the next time permalinks are saved.

Generate rules instead of typing them

The .htaccess generator builds the default block plus the additions above from checkboxes, with the correct order and syntax. Review the output, then paste it in using the safety routine.

Troubleshooting

  • 500 error after saving: restore your backup; check for a missing closing tag or a rule that needs a module your host does not have.
  • Posts show 404 but the home page works: the WordPress block is missing or mod_rewrite is off. Save Settings → Permalinks again.
  • Redirect loop: two rules (or a rule and your CDN) are redirecting back and forth, usually HTTPS or www rules.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *