Type something to search...
How to disable directory browsing in WordPress?

How to disable directory browsing in WordPress?

To disable directory browsing in WordPress on an Apache or LiteSpeed server, add the single line Options -Indexes to the .htaccess file in your site's root folder. On Nginx, make sure autoindex is set to off (the default) in your server configuration. Once that's done, anyone who opens a folder like /wp-content/uploads/ in their browser gets a 403 Forbidden error instead of a clickable list of every file inside it.

Directory browsing is one of those small misconfigurations that's easy to overlook and easy to fix. In this guide, you'll learn what directory browsing is and why it matters, how to check whether your site is affected, how to turn it off on every common web server, and what to do if the fix causes an error.

What Is Directory Browsing?

Directory browsing, also called directory listing or directory indexing, is a web server feature that displays the contents of a folder when there's no index file in it. Normally, when you visit a folder URL such as https://example.com/blog/, the server looks for a default file like index.php or index.html and serves that. If it can't find one and directory listing is enabled, it generates a plain page titled something like "Index of /wp-content/uploads/2026/09" with links to every file and subfolder.

On a WordPress site, the folders most likely to be exposed are:

  • /wp-content/uploads/ and its year and month subfolders, which WordPress doesn't protect with index files by default.
  • Plugin subfolders, such as folders for assets, logs, or exports that the plugin author didn't protect.
  • Backup and cache folders, created by some backup, caching, or form plugins.
  • Custom folders you or a developer created in the web root.

WordPress core does include small index.php files in some folders, like wp-content/, wp-content/plugins/, and wp-content/themes/. They contain only the comment "Silence is golden" and exist precisely to stop directory listings in those locations. But they don't cover every folder, which is why the server-level setting matters.

Why Directory Browsing Is a Security Risk

An exposed directory listing doesn't give anyone the ability to change your site, but it hands out information that makes other attacks easier:

  1. It reveals your plugins and themes: A listing of plugin folders tells an attacker exactly which plugins you use, and the files inside can reveal their versions. That makes it easy to look up known vulnerabilities.
  2. It exposes private files: Uploads folders sometimes contain files that were never meant to be public, like invoices, form attachments, exported CSVs, or draft documents that were uploaded but never linked.
  3. It can expose backups and logs: Some plugins store database backups, export files, or debug logs in predictable folders. A browsable folder makes them trivial to find and download.
  4. It helps with reconnaissance: Seeing your folder structure helps attackers understand your setup and find stray files like old test scripts.
  5. It can hurt your privacy and SEO: Search engines can index directory listings, so file names and documents may show up in search results.

Because turning it off takes seconds and has no downside for a normal WordPress site, there's no good reason to leave it on.

How to Check If Directory Browsing Is Enabled

Testing takes a minute. Open a private browser window and visit a folder that probably doesn't contain an index file:

https://example.com/wp-content/uploads/
https://example.com/wp-content/uploads/2026/
https://example.com/wp-includes/

Here's how to read the results:

  • "Index of ..." with a file list: Directory browsing is enabled. You need to fix it.
  • 403 Forbidden: Directory browsing is disabled. You're fine.
  • A blank white page: There's an index file in that folder (like WordPress's "Silence is golden" file). Try a deeper folder to be sure.
  • Your theme's 404 page: The request was passed to WordPress, which usually means listings are off for that path.

You can also check from the command line. If the response contains "Index of", listings are on:

curl -s https://example.com/wp-content/uploads/ | grep -i "index of"

Method 1: Disable Directory Browsing on Apache or LiteSpeed

Most shared hosting runs Apache or LiteSpeed, and both read .htaccess files.

  1. Back up your .htaccess file: Connect to your site with SFTP or your hosting file manager and download a copy of the .htaccess file in your WordPress root folder, the same folder that contains wp-config.php.
  2. Show hidden files if needed: Files that start with a dot are hidden by default in many file managers. In cPanel's File Manager, open Settings and tick Show Hidden Files (dotfiles).
  3. Edit the file: Open .htaccess and add the following line at the very top, above the # BEGIN WordPress marker.
  4. Save and test: Save the file and revisit the folder URLs from the previous section in a private window.
# Disable directory listings site-wide
Options -Indexes

Put it outside the # BEGIN WordPress and # END WordPress block. WordPress rewrites everything between those markers when you save your permalink settings, so anything you add inside them can be lost.

The -Indexes option applies to the folder containing the .htaccess file and every folder below it, so one line in the root covers your entire site.

If You Get a 500 Internal Server Error

If your site shows a 500 error right after adding the line, your server doesn't allow the Options directive in .htaccess files. Remove the line to restore your site, then choose one of these options:

  • Ask your host: Many hosts can disable directory listing for you, or already offer a setting for it.
  • Use the cPanel Indexes tool: See the next section.
  • Edit the server config: If you manage the server, use the virtual host method below.

Disabling Listings in the Apache Virtual Host

If you have root access to your server, setting this in the main configuration is cleaner and slightly faster than .htaccess, because Apache doesn't need to read the file on every request. On Ubuntu or Debian, edit your site's config in /etc/apache2/sites-available/:

<VirtualHost *:443>
    ServerName example.com
    DocumentRoot /var/www/example.com/public_html

    <Directory /var/www/example.com/public_html>
        Options -Indexes +FollowSymLinks
        AllowOverride All
        Require all granted
    </Directory>

    # ... your SSL and other settings ...
</VirtualHost>

Then check the configuration and reload Apache:

sudo apachectl configtest && sudo systemctl reload apache2

# RHEL, Rocky, or AlmaLinux:
# sudo apachectl configtest && sudo systemctl reload httpd

You can also disable listings for every site on the server by editing the default <Directory /var/www/> block in /etc/apache2/apache2.conf and changing Options Indexes FollowSymLinks to Options -Indexes +FollowSymLinks.

Method 2: Use the cPanel Indexes Tool

If you're on cPanel hosting and prefer not to edit files:

  1. Log in to cPanel: Open your hosting control panel.
  2. Open Indexes: Find the Indexes tool in the Advanced section.
  3. Select your folder: Click Edit next to your site's root folder, usually public_html.
  4. Choose No Indexing: Select No Indexing and click Save.

cPanel writes the correct directive to the .htaccess file for you. Other control panels like Plesk and DirectAdmin have similar settings in their Apache or web server sections.

Method 3: Disable Directory Browsing on Nginx

Nginx has directory listings turned off by default. They're only enabled when a configuration contains autoindex on;. If your test showed a directory listing on an Nginx server, search your configuration for it:

# Find any place where autoindex is enabled
sudo grep -rn "autoindex" /etc/nginx/

Change any autoindex on; to autoindex off;, or remove the line entirely. You can also set it explicitly in your server block to be safe:

server {
    listen 443 ssl;
    server_name example.com;
    root /var/www/example.com/public_html;
    index index.php index.html;

    # Explicitly disable directory listings
    autoindex off;

    location / {
        try_files $uri $uri/ /index.php?$args;
    }

    # ... PHP and other location blocks ...
}

Test the configuration and reload:

sudo nginx -t && sudo systemctl reload nginx

With the standard WordPress try_files rule shown above, a request for a folder without an index file on Nginx is usually passed to WordPress, which returns your theme's 404 page. That's expected and perfectly safe.

Method 4: Disable Directory Browsing on IIS

If your WordPress site runs on Windows with IIS, directory browsing is controlled in web.config. Add the directoryBrowse element inside system.webServer:

<?xml version="1.0" encoding="UTF-8"?>
<configuration>
  <system.webServer>
    <directoryBrowse enabled="false" />
    <!-- your existing rewrite rules stay here -->
  </system.webServer>
</configuration>

If you already have a web.config with WordPress rewrite rules, add only the directoryBrowse line inside the existing system.webServer element rather than replacing the file.

A Fallback: Add Empty Index Files

If you can't change server settings at all, you can place an empty index.html file in each folder you want to protect. The server will serve that blank file instead of a listing. This is how WordPress protects its own wp-content/plugins/ and wp-content/themes/ folders, using index.php files.

For the uploads folder, use index.html rather than index.php. Many hardening guides recommend blocking PHP execution inside uploads, and a PHP file there would work against that. Here's a command to add an empty index.html to every folder in uploads that doesn't already have an index file:

# Run from your WordPress root folder
find wp-content/uploads -type d -exec sh -c \
  '[ -e "$1/index.html" ] || [ -e "$1/index.php" ] || touch "$1/index.html"' _ {} \;

The downside is that WordPress creates new month folders automatically, and those won't have index files unless you rerun the command. That's why the server setting is always the better fix.

Some Security Plugins Can Help

Several popular security plugins can check for or fix directory browsing for you:

  • All-In-One Security (AIOS): Includes a setting to disable directory index views through .htaccess.
  • Sucuri Security: Its hardening section and scanner can flag directory listing issues.
  • Solid Security: Its site scan and security check features can identify common server hardening gaps.

These plugins typically add the same Options -Indexes line to your .htaccess file. They're convenient, but they can only help on Apache or LiteSpeed. On Nginx, you still need to check the server configuration.

After Disabling Directory Browsing

Once listings are off, take a moment to check what was exposed while they were on:

  • Look for sensitive files in uploads: Search for files like .sql, .zip, .csv, or .log in wp-content/uploads/ and remove anything that shouldn't be there.
  • Move backups off the web server: Store backups in remote storage rather than a public folder.
  • Search Google for exposed listings: Search for site:example.com "index of" to see if any listings were indexed, and request removal in Google Search Console if needed.
  • Review plugin folders: Check whether any plugin writes exports or logs to a public folder, and change its settings if possible.

FAQ: Disabling Directory Browsing in WordPress

It tells Apache not to generate a file listing when someone opens a folder that doesn't have an index file. Instead, the server returns a 403 Forbidden error.

No. WordPress never relies on directory listings, so turning them off has no effect on normal pages, images, or plugins. Direct links to individual files keep working.

Your server doesn't allow the Options directive in .htaccess files. Remove the line, then ask your host to disable listings or use the cPanel Indexes tool instead.

No. Nginx only lists directories when autoindex is set to on. If you see listings on Nginx, search your configuration for autoindex and turn it off.

At the top of the .htaccess file in your WordPress root folder, outside the BEGIN WordPress and END WordPress markers so it isn't overwritten.

They don't hurt and WordPress adds them automatically in some folders. With directory listings disabled at the server level, they're just an extra safety net.


Conclusion

Disabling directory browsing is one of the quickest hardening steps you can take on a WordPress site. On Apache and LiteSpeed, a single Options -Indexes line in your root .htaccess file does the job; on Nginx, you just need to make sure autoindex isn't turned on; and on IIS, one line in web.config covers it. Test a few folder URLs before and after, and you'll know within minutes whether your site was exposing its file structure.

Once it's done, use the opportunity to clean up anything that shouldn't be in a public folder, like old backups, exports, or logs. Directory browsing on its own rarely causes a breach, but it makes finding weaknesses much easier, so closing it off is a small change with a worthwhile payoff.

Share :

Related Posts

What are the best WordPress security plugins?

What are the best WordPress security plugins?

The best WordPress security plugins for most sites are Wordfence, Sucuri Security, Solid Security, MalCare, All-In-One Security (AIOS), Patchstack, a

Dive Deeper
What are the most common website security threats?

What are the most common website security threats?

The most common website security threats are vulnerable or outdated software, weak and stolen passwords, malware infections, injection attacks like S

Dive Deeper
What is the difference between posts and pages in WordPress?

What is the difference between posts and pages in WordPress?

The main difference between posts and pages in WordPress is that posts are timely, dated entries that appear in your blog feed, archives, and RSS fee

Dive Deeper