
How to disable directory browsing in WordPress?
- Sajjad
- WordPress, Security
- 09 Sep, 2026
To disable directory browsing in WordPress on an Apache or LiteSpeed server, add the single line Options -Indexes to the .htaccess file in your site's root folder. On Nginx, make sure autoindex is set to off (the default) in your server configuration. Once that's done, anyone who opens a folder like /wp-content/uploads/ in their browser gets a 403 Forbidden error instead of a clickable list of every file inside it.
Directory browsing is one of those small misconfigurations that's easy to overlook and easy to fix. In this guide, you'll learn what directory browsing is and why it matters, how to check whether your site is affected, how to turn it off on every common web server, and what to do if the fix causes an error.
What Is Directory Browsing?
Directory browsing, also called directory listing or directory indexing, is a web server feature that displays the contents of a folder when there's no index file in it. Normally, when you visit a folder URL such as https://example.com/blog/, the server looks for a default file like index.php or index.html and serves that. If it can't find one and directory listing is enabled, it generates a plain page titled something like "Index of /wp-content/uploads/2026/09" with links to every file and subfolder.
On a WordPress site, the folders most likely to be exposed are:
/wp-content/uploads/and its year and month subfolders, which WordPress doesn't protect with index files by default.- Plugin subfolders, such as folders for assets, logs, or exports that the plugin author didn't protect.
- Backup and cache folders, created by some backup, caching, or form plugins.
- Custom folders you or a developer created in the web root.
WordPress core does include small index.php files in some folders, like wp-content/, wp-content/plugins/, and wp-content/themes/. They contain only the comment "Silence is golden" and exist precisely to stop directory listings in those locations. But they don't cover every folder, which is why the server-level setting matters.
Why Directory Browsing Is a Security Risk
An exposed directory listing doesn't give anyone the ability to change your site, but it hands out information that makes other attacks easier:
- It reveals your plugins and themes: A listing of plugin folders tells an attacker exactly which plugins you use, and the files inside can reveal their versions. That makes it easy to look up known vulnerabilities.
- It exposes private files: Uploads folders sometimes contain files that were never meant to be public, like invoices, form attachments, exported CSVs, or draft documents that were uploaded but never linked.
- It can expose backups and logs: Some plugins store database backups, export files, or debug logs in predictable folders. A browsable folder makes them trivial to find and download.
- It helps with reconnaissance: Seeing your folder structure helps attackers understand your setup and find stray files like old test scripts.
- It can hurt your privacy and SEO: Search engines can index directory listings, so file names and documents may show up in search results.
Because turning it off takes seconds and has no downside for a normal WordPress site, there's no good reason to leave it on.
How to Check If Directory Browsing Is Enabled
Testing takes a minute. Open a private browser window and visit a folder that probably doesn't contain an index file:
https://example.com/wp-content/uploads/
https://example.com/wp-content/uploads/2026/
https://example.com/wp-includes/
Here's how to read the results:
- "Index of ..." with a file list: Directory browsing is enabled. You need to fix it.
- 403 Forbidden: Directory browsing is disabled. You're fine.
- A blank white page: There's an index file in that folder (like WordPress's "Silence is golden" file). Try a deeper folder to be sure.
- Your theme's 404 page: The request was passed to WordPress, which usually means listings are off for that path.
You can also check from the command line. If the response contains "Index of", listings are on:
curl -s https://example.com/wp-content/uploads/ | grep -i "index of"
Method 1: Disable Directory Browsing on Apache or LiteSpeed
Most shared hosting runs Apache or LiteSpeed, and both read .htaccess files.
- Back up your .htaccess file: Connect to your site with SFTP or your hosting file manager and download a copy of the
.htaccessfile in your WordPress root folder, the same folder that containswp-config.php. - Show hidden files if needed: Files that start with a dot are hidden by default in many file managers. In cPanel's File Manager, open Settings and tick Show Hidden Files (dotfiles).
- Edit the file: Open
.htaccessand add the following line at the very top, above the# BEGIN WordPressmarker. - Save and test: Save the file and revisit the folder URLs from the previous section in a private window.
# Disable directory listings site-wide
Options -Indexes
Put it outside the # BEGIN WordPress and # END WordPress block. WordPress rewrites everything between those markers when you save your permalink settings, so anything you add inside them can be lost.
The -Indexes option applies to the folder containing the .htaccess file and every folder below it, so one line in the root covers your entire site.
If You Get a 500 Internal Server Error
If your site shows a 500 error right after adding the line, your server doesn't allow the Options directive in .htaccess files. Remove the line to restore your site, then choose one of these options:
- Ask your host: Many hosts can disable directory listing for you, or already offer a setting for it.
- Use the cPanel Indexes tool: See the next section.
- Edit the server config: If you manage the server, use the virtual host method below.
Disabling Listings in the Apache Virtual Host
If you have root access to your server, setting this in the main configuration is cleaner and slightly faster than .htaccess, because Apache doesn't need to read the file on every request. On Ubuntu or Debian, edit your site's config in /etc/apache2/sites-available/:
<VirtualHost *:443>
ServerName example.com
DocumentRoot /var/www/example.com/public_html
<Directory /var/www/example.com/public_html>
Options -Indexes +FollowSymLinks
AllowOverride All
Require all granted
</Directory>
# ... your SSL and other settings ...
</VirtualHost>
Then check the configuration and reload Apache:
sudo apachectl configtest && sudo systemctl reload apache2
# RHEL, Rocky, or AlmaLinux:
# sudo apachectl configtest && sudo systemctl reload httpd
You can also disable listings for every site on the server by editing the default <Directory /var/www/> block in /etc/apache2/apache2.conf and changing Options Indexes FollowSymLinks to Options -Indexes +FollowSymLinks.
Method 2: Use the cPanel Indexes Tool
If you're on cPanel hosting and prefer not to edit files:
- Log in to cPanel: Open your hosting control panel.
- Open Indexes: Find the Indexes tool in the Advanced section.
- Select your folder: Click Edit next to your site's root folder, usually
public_html. - Choose No Indexing: Select No Indexing and click Save.
cPanel writes the correct directive to the .htaccess file for you. Other control panels like Plesk and DirectAdmin have similar settings in their Apache or web server sections.
Method 3: Disable Directory Browsing on Nginx
Nginx has directory listings turned off by default. They're only enabled when a configuration contains autoindex on;. If your test showed a directory listing on an Nginx server, search your configuration for it:
# Find any place where autoindex is enabled
sudo grep -rn "autoindex" /etc/nginx/
Change any autoindex on; to autoindex off;, or remove the line entirely. You can also set it explicitly in your server block to be safe:
server {
listen 443 ssl;
server_name example.com;
root /var/www/example.com/public_html;
index index.php index.html;
# Explicitly disable directory listings
autoindex off;
location / {
try_files $uri $uri/ /index.php?$args;
}
# ... PHP and other location blocks ...
}
Test the configuration and reload:
sudo nginx -t && sudo systemctl reload nginx
With the standard WordPress try_files rule shown above, a request for a folder without an index file on Nginx is usually passed to WordPress, which returns your theme's 404 page. That's expected and perfectly safe.
Method 4: Disable Directory Browsing on IIS
If your WordPress site runs on Windows with IIS, directory browsing is controlled in web.config. Add the directoryBrowse element inside system.webServer:
<?xml version="1.0" encoding="UTF-8"?>
<configuration>
<system.webServer>
<directoryBrowse enabled="false" />
<!-- your existing rewrite rules stay here -->
</system.webServer>
</configuration>
If you already have a web.config with WordPress rewrite rules, add only the directoryBrowse line inside the existing system.webServer element rather than replacing the file.
A Fallback: Add Empty Index Files
If you can't change server settings at all, you can place an empty index.html file in each folder you want to protect. The server will serve that blank file instead of a listing. This is how WordPress protects its own wp-content/plugins/ and wp-content/themes/ folders, using index.php files.
For the uploads folder, use index.html rather than index.php. Many hardening guides recommend blocking PHP execution inside uploads, and a PHP file there would work against that. Here's a command to add an empty index.html to every folder in uploads that doesn't already have an index file:
# Run from your WordPress root folder
find wp-content/uploads -type d -exec sh -c \
'[ -e "$1/index.html" ] || [ -e "$1/index.php" ] || touch "$1/index.html"' _ {} \;
The downside is that WordPress creates new month folders automatically, and those won't have index files unless you rerun the command. That's why the server setting is always the better fix.
Some Security Plugins Can Help
Several popular security plugins can check for or fix directory browsing for you:
- All-In-One Security (AIOS): Includes a setting to disable directory index views through
.htaccess. - Sucuri Security: Its hardening section and scanner can flag directory listing issues.
- Solid Security: Its site scan and security check features can identify common server hardening gaps.
These plugins typically add the same Options -Indexes line to your .htaccess file. They're convenient, but they can only help on Apache or LiteSpeed. On Nginx, you still need to check the server configuration.
After Disabling Directory Browsing
Once listings are off, take a moment to check what was exposed while they were on:
- Look for sensitive files in uploads: Search for files like
.sql,.zip,.csv, or.loginwp-content/uploads/and remove anything that shouldn't be there. - Move backups off the web server: Store backups in remote storage rather than a public folder.
- Search Google for exposed listings: Search for
site:example.com "index of"to see if any listings were indexed, and request removal in Google Search Console if needed. - Review plugin folders: Check whether any plugin writes exports or logs to a public folder, and change its settings if possible.
FAQ: Disabling Directory Browsing in WordPress
It tells Apache not to generate a file listing when someone opens a folder that doesn't have an index file. Instead, the server returns a 403 Forbidden error.
No. WordPress never relies on directory listings, so turning them off has no effect on normal pages, images, or plugins. Direct links to individual files keep working.
Your server doesn't allow the Options directive in .htaccess files. Remove the line, then ask your host to disable listings or use the cPanel Indexes tool instead.
No. Nginx only lists directories when autoindex is set to on. If you see listings on Nginx, search your configuration for autoindex and turn it off.
At the top of the .htaccess file in your WordPress root folder, outside the BEGIN WordPress and END WordPress markers so it isn't overwritten.
They don't hurt and WordPress adds them automatically in some folders. With directory listings disabled at the server level, they're just an extra safety net.
Conclusion
Disabling directory browsing is one of the quickest hardening steps you can take on a WordPress site. On Apache and LiteSpeed, a single Options -Indexes line in your root .htaccess file does the job; on Nginx, you just need to make sure autoindex isn't turned on; and on IIS, one line in web.config covers it. Test a few folder URLs before and after, and you'll know within minutes whether your site was exposing its file structure.
Once it's done, use the opportunity to clean up anything that shouldn't be in a public folder, like old backups, exports, or logs. Directory browsing on its own rarely causes a breach, but it makes finding weaknesses much easier, so closing it off is a small change with a worthwhile payoff.


