← all tools

WordPress .htaccess generator

The standard Apache rewrite block for single-site or multisite, plus optional hardening rules.

Optional hardening
.htaccess — WordPress root
# Custom rules. WordPress rewrites everything between the
# BEGIN/END WordPress markers, so keep your own directives above them.

# Do not list the contents of directories that have no index file.
Options -Indexes

# Block direct requests for the WordPress credentials file.
<Files "wp-config.php">
  <IfModule mod_authz_core.c>
    Require all denied
  </IfModule>
  <IfModule !mod_authz_core.c>
    Order allow,deny
    Deny from all
  </IfModule>
</Files>

# Block direct requests for Apache configuration files.
<FilesMatch "^\.ht(access|passwd)$">
  <IfModule mod_authz_core.c>
    Require all denied
  </IfModule>
  <IfModule !mod_authz_core.c>
    Order allow,deny
    Deny from all
  </IfModule>
</FilesMatch>

# BEGIN WordPress
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>
# END WordPress

WordPress rewrites everything between # BEGIN WordPress and # END WordPress, so hardening rules are placed above that block. Back up the current file first. On nginx, LiteSpeed without .htaccess support, or IIS, these rules are ignored — the equivalents belong in the server configuration.

Quick answers

Where does the WordPress .htaccess file live?

In the site's root directory, alongside wp-config.php — the same folder wp-login.php is in. Multisite subdirectory networks use one .htaccess at the root; multisite subdomain networks do too, with different rewrite rules.

Why do my custom rules keep disappearing?

WordPress rewrites everything between # BEGIN WordPress and # END WordPress whenever permalinks are saved. Rules placed inside that block are overwritten; place custom rules above or below it instead, as this generator does.

Does this work on nginx?

No — .htaccess is an Apache (and LiteSpeed-with-Apache-compatibility) mechanism. nginx ignores the file entirely; the equivalent directives belong in the server block, which on most managed hosts only the provider can edit. The HTTPS redirect loop guide has the nginx form of the TLS redirect, and the uploads hardening guide has the nginx form of the PHP block.