Skip to content

Search WPDesignVault

Try "image", "json", "schema" or "contrast". Use arrow keys to move through results.

WordPress Guides

wp-config.php Explained: Every Setting Worth Knowing

wp-config.php is the first file WordPress reads on every request. It holds your database details, security keys and dozens of optional switches for debugging, performance and security. Most sites only ever touch…

On this page

wp-config.php is the first file WordPress reads on every request. It holds your database details, security keys and dozens of optional switches for debugging, performance and security. Most sites only ever touch a few lines, but knowing what is possible saves a lot of guesswork. This guide walks through the settings worth knowing, grouped by purpose.

Before you edit

  • Download a backup copy first. A syntax error here shows a blank page or a fatal error on the whole site.
  • Add custom settings above the line that says /* That's all, stop editing! Happy publishing. */. Anything below it runs too late.
  • Use a plain text editor, not a word processor, so quotes stay straight.

Database connection

define( 'DB_NAME', 'database_name' );
define( 'DB_USER', 'database_user' );
define( 'DB_PASSWORD', 'a-long-random-password' );
define( 'DB_HOST', 'localhost' );
define( 'DB_CHARSET', 'utf8mb4' );
define( 'DB_COLLATE', '' );
$table_prefix = 'wp_';

Your host provides the first four. utf8mb4 supports every Unicode character including emoji; leave DB_COLLATE empty unless you know you need a specific collation. A custom table prefix is set at install time; changing it later requires renaming tables and some option and meta keys, so it is not worth doing on an existing site for “security”.

Security keys and salts

Eight constants (AUTH_KEY, SECURE_AUTH_KEY, LOGGED_IN_KEY, NONCE_KEY and their _SALT partners) sign login cookies and nonces. They should be long and random. Replacing them logs everyone out, which is exactly what you want after a suspected compromise. Generate a fresh set with the salt generator, which uses your browser’s cryptographic random generator.

Debugging

define( 'WP_DEBUG', true );
define( 'WP_DEBUG_LOG', true );
define( 'WP_DEBUG_DISPLAY', false );
@ini_set( 'display_errors', 0 );

This combination records errors to wp-content/debug.log without showing them to visitors. Never leave WP_DEBUG_DISPLAY on for a live site: error messages reveal file paths and plugin details. You can set WP_DEBUG_LOG to a path outside the web root, such as ‘/home/user/logs/wp-errors.log’, so the log is not downloadable. Turn debugging off again when you have finished.

SCRIPT_DEBUG loads unminified core scripts, useful when debugging the block editor. SAVEQUERIES records every database query for profiling; it slows the site, so only use it briefly.

Environment

define( 'WP_ENVIRONMENT_TYPE', 'staging' );

Values are local, development, staging and production. Plugins and themes can read it with wp_get_environment_type() to, for example, disable emails or analytics on staging.

Site address

define( 'WP_HOME', 'https://example.com' );
define( 'WP_SITEURL', 'https://example.com' );

These override the addresses stored in Settings → General and lock those fields. They are a quick fix when a wrong address locks you out of the admin, for example after a migration.

Performance and resources

  • WP_MEMORY_LIMIT (‘256M’) raises the memory available to WordPress on the front end, up to the server’s PHP limit. WP_MAX_MEMORY_LIMIT does the same for admin tasks.
  • WP_POST_REVISIONS (for example 10) limits stored revisions per post; false turns them off. Limiting is better than disabling.
  • AUTOSAVE_INTERVAL (seconds) changes how often the editor autosaves.
  • EMPTY_TRASH_DAYS controls how long trashed items are kept (default 30).
  • DISABLE_WP_CRON stops WordPress running scheduled tasks on page visits. Only set it if you add a real server cron job that requests wp-cron.php, otherwise scheduled posts and updates stop.

Security hardening

  • DISALLOW_FILE_EDIT (true) removes the theme and plugin code editors from the dashboard, so a stolen admin login cannot be used to edit PHP. Recommended on almost every site.
  • DISALLOW_FILE_MODS (true) also blocks installing and updating plugins and themes from the dashboard. Only use it if updates are deployed another way.
  • FORCE_SSL_ADMIN (true) requires HTTPS for logins and the dashboard.
  • WP_AUTO_UPDATE_CORE (‘minor’ or true) controls automatic core updates. Keeping at least minor (security) releases automatic is wise.

Moving files out of the web root

WordPress looks for wp-config.php one level above the WordPress folder if it is not found in the folder itself. On hosts that allow it, moving it up keeps it outside the publicly served directory. Many managed hosts already protect the file, so check before moving it.

Generate a clean file

The wp-config.php generator builds a complete file with fresh keys and the options above as checkboxes. Compare its output with your current file rather than replacing yours blindly: your host may add its own lines that must stay.

Quick reference

GoalConstant
Log errors privatelyWP_DEBUG + WP_DEBUG_LOG, WP_DEBUG_DISPLAY false
Log everyone outReplace the eight keys and salts
Remove the code editorsDISALLOW_FILE_EDIT
Fix a wrong site URLWP_HOME and WP_SITEURL
Fewer revisionsWP_POST_REVISIONS
Mark a staging siteWP_ENVIRONMENT_TYPE

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *