The Default WordPress .htaccess File (and Safe Additions)
If your WordPress site runs on Apache or LiteSpeed, a small file called .htaccess decides how pretty permalinks work, and it is also where many redirects, security rules and caching headers end…
On this page
If your WordPress site runs on Apache or LiteSpeed, a small file called .htaccess decides how pretty permalinks work, and it is also where many redirects, security rules and caching headers end up. A single typo in it can take the whole site offline with a 500 error. This guide shows the default file, explains every line, and lists additions that are safe and useful.
Where the file lives
.htaccess sits in the same folder as wp-config.php, usually the web root. The leading dot makes it hidden in many file managers and FTP clients, so turn on “show hidden files” if you cannot see it. Nginx servers ignore .htaccess completely; on Nginx the equivalent rules live in the server configuration, which your host manages.
The default WordPress rules
When you save Settings → Permalinks with any structure other than “Plain”, WordPress writes this block:
# BEGIN WordPress
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>
# END WordPress
What each line does
- # BEGIN / # END WordPress: markers. WordPress rewrites everything between them whenever permalinks are saved, so never put your own rules inside.
- IfModule mod_rewrite.c: only run the rules if the rewrite module is available, so a missing module does not cause an error.
- RewriteEngine On: turns on URL rewriting.
- HTTP_AUTHORIZATION: passes the Authorization header to PHP, which application passwords and some REST API clients need.
- RewriteBase /: the base path. If WordPress is installed in a subfolder, this becomes /subfolder/.
- ^index\.php$ – [L]: if the request is already index.php, stop.
- The two RewriteCond lines: if the request is not a real file (-f) and not a real directory (-d)…
- RewriteRule . /index.php [L]: …send it to index.php, where WordPress works out which post or page was requested.
Those last three lines are why images, CSS and uploads load directly while every pretty URL goes through WordPress.
Before you edit: a safety routine
- Download a copy of the current file and keep it.
- Make one change at a time.
- Load the home page, a post, an image and the admin area after each change.
- If you see “500 Internal Server Error”, restore the copy immediately, then look for the typo.
Safe, useful additions
Put your own rules above the # BEGIN WordPress line so WordPress never overwrites them and so redirects run before WordPress routing.
Force HTTPS
RewriteEngine On
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
Only add this once your SSL certificate works on every URL. Behind some load balancers or CDNs, %{HTTPS} is always off; in that case use the redirect setting in your host or CDN instead to avoid a redirect loop.
Choose www or non-www
RewriteCond %{HTTP_HOST} ^www\.(.+)$ [NC]
RewriteRule ^ https://%1%{REQUEST_URI} [L,R=301]
This sends www to the bare domain. Make sure the Site Address in Settings → General matches the version you choose.
Block access to sensitive files
<FilesMatch "^(wp-config\.php|readme\.html|license\.txt|\.htaccess)$">
Require all denied
</FilesMatch>
Require all denied is Apache 2.4 syntax. On very old Apache 2.2 servers the equivalent is Order allow,deny / Deny from all.
Turn off directory listings
Options -Indexes
Disable PHP in the uploads folder
Create a separate .htaccess inside wp-content/uploads containing:
<FilesMatch "\.(php|phtml|phar)$">
Require all denied
</FilesMatch>
Uploads should only ever contain media. This stops an uploaded script from running if something malicious gets in.
What not to put in .htaccess
- Hundreds of individual redirects. Every request reads the file, so very long files slow the server. Use a redirect plugin or server config for large migrations.
- Rules copied from old tutorials that use mod_access syntax or block whole countries by IP lists.
- Anything inside the WordPress markers. It will disappear the next time permalinks are saved.
Generate rules instead of typing them
The .htaccess generator builds the default block plus the additions above from checkboxes, with the correct order and syntax. Review the output, then paste it in using the safety routine.
Troubleshooting
- 500 error after saving: restore your backup; check for a missing closing tag or a rule that needs a module your host does not have.
- Posts show 404 but the home page works: the WordPress block is missing or mod_rewrite is off. Save Settings → Permalinks again.
- Redirect loop: two rules (or a rule and your CDN) are redirecting back and forth, usually HTTPS or www rules.
More guides
A Maintenance Checklist for Small WordPress Sites
Planned article. Write the full piece here, then delete this brief.
How to Set Up 301 Redirects in WordPress Without a Plugin
When a URL changes, a 301 redirect sends visitors and search engines to the new address and tells them the move is…
wp-config.php Explained: Every Setting Worth Knowing
wp-config.php is the first file WordPress reads on every request. It holds your database details, security keys and dozens of optional switches…
Comments