Type something to search...
How to disable file editing in the WordPress dashboard?

How to disable file editing in the WordPress dashboard?

To disable file editing in the WordPress dashboard, add define( 'DISALLOW_FILE_EDIT', true ); to your wp-config.php file, above the line that says "That's all, stop editing!" Once saved, the Theme File Editor and Plugin File Editor screens disappear from the admin menu, and nobody, not even an administrator, can edit PHP files from inside WordPress. It's a one-line change that removes a powerful tool attackers love to abuse.

The built-in editors are convenient for quick tweaks, but they're also a direct path from "someone got into an admin account" to "someone is running their own code on your server." This article explains what the file editors do, why disabling them is a recommended security practice, how to do it safely (with or without FTP), how to verify it worked, and how to make code changes afterwards.

What Is the WordPress File Editor?

WordPress includes two built-in code editors in the dashboard:

  • Theme File Editor: Found under Appearance > Theme File Editor in classic themes, or Tools > Theme File Editor for block themes. It lets administrators edit theme files, including functions.php, template files, and stylesheets.
  • Plugin File Editor: Found under Plugins > Plugin File Editor (or Tools > Plugin File Editor when the theme editor lives under Tools). It lets administrators edit the PHP files of any installed plugin.

Both editors write directly to files on your server. Since WordPress 4.9, the editor tries to catch fatal PHP errors and roll back the change, and it shows a warning before you edit. But it doesn't provide version control, testing, or any protection against deliberately malicious code.

Why Should You Disable File Editing?

It Turns an Admin Compromise Into Code Execution

If an attacker obtains an administrator's password through phishing, credential stuffing, or a session hijack, the file editor lets them paste PHP straight into functions.php or a plugin file. That code runs on every page load. From there, they can create hidden admin users, install backdoors, send spam, steal data, or pivot to other sites on the same server.

Disabling the editor doesn't stop every possible abuse of an admin account, since an admin can still upload plugins unless you also disable file modifications. But it removes the quickest and quietest route.

It Prevents Accidental Site Breakage

Even with WordPress's error protection, a typo in functions.php can still cause problems, and some changes break things without a fatal error. Editing files through a proper workflow, with a backup and ideally a staging site, is much safer.

Changes Get Overwritten Anyway

Edits made to a parent theme or plugin are lost the next time that theme or plugin updates. Anything you'd change in the editor belongs in a child theme or a small custom plugin instead, which you should manage outside the dashboard.

It's a Widely Recommended Hardening Step

The WordPress developer documentation on hardening recommends disabling file editing, and most security plugins include it as a one-click setting. It's one of the easiest ways to reduce your site's attack surface without affecting visitors.

Before You Start

You'll need access to your wp-config.php file, which lives in the root of your WordPress installation (the same folder as wp-admin and wp-content). You can reach it through:

  • An SFTP client like FileZilla or Cyberduck.
  • Your hosting control panel's file manager (cPanel, Plesk, or a custom dashboard).
  • SSH, if your host supports it.

Before editing, download a copy of wp-config.php so you can restore it if anything goes wrong.

Method 1: Add DISALLOW_FILE_EDIT to wp-config.php

This is the standard, recommended method.

  • Open wp-config.php: Connect to your site and open the file in a plain text editor. Don't use a word processor, which can add hidden formatting.

  • Find the stop-editing line: Look for this comment near the bottom of the file:

/* That's all, stop editing! Happy publishing. */
  • Add the constant above it: Paste this line directly above that comment:
define( 'DISALLOW_FILE_EDIT', true );
  • Save and upload: Save the file and upload it back to the server, replacing the original.

  • Refresh your dashboard: The Theme File Editor and Plugin File Editor menu items should now be gone.

Here's how the relevant part of the file might look afterwards:

/**
 * For developers: WordPress debugging mode.
 */
define( 'WP_DEBUG', false );

/* Disable the theme and plugin file editors in the dashboard. */
define( 'DISALLOW_FILE_EDIT', true );

/* That's all, stop editing! Happy publishing. */

/** Absolute path to the WordPress directory. */
if ( ! defined( 'ABSPATH' ) ) {
    define( 'ABSPATH', __DIR__ . '/' );
}

/** Sets up WordPress vars and included files. */
require_once ABSPATH . 'wp-settings.php';

The placement matters. If you add it after require_once ABSPATH . 'wp-settings.php';, WordPress has already loaded and the constant may not take effect.

Method 2: Use WP-CLI

If you have SSH access and WP-CLI installed, you can add the constant with a single command from your WordPress root:

wp config set DISALLOW_FILE_EDIT true --raw

The --raw flag writes true as a PHP boolean rather than the string 'true'. You can confirm the setting with:

wp config get DISALLOW_FILE_EDIT

WP-CLI places the constant in the correct position automatically.

Method 3: Use a Security Plugin

Many security plugins include a setting to disable file editing, which writes the constant for you or blocks the editor through code:

  • Solid Security: Look in its WordPress tweaks or hardening settings for an option to disable the file editor.
  • All-In-One Security (AIOS): Offers a file editing option in its filesystem security settings.

Menu names change between plugin versions, so check the plugin's documentation if you can't find the setting. Remember that if the plugin enforces the setting through code, deactivating the plugin brings the editor back. The wp-config.php method is more robust because it doesn't depend on any plugin staying active.

Going Further: DISALLOW_FILE_MODS

DISALLOW_FILE_EDIT only removes the editors. Administrators can still install, update, and delete plugins and themes, which means a compromised admin account could still upload a malicious plugin.

If you want to lock things down completely, there's a stronger constant:

define( 'DISALLOW_FILE_MODS', true );

This disables:

  • The theme and plugin file editors (it implies DISALLOW_FILE_EDIT).
  • Installing new plugins and themes from the dashboard.
  • Updating plugins, themes, and WordPress core from the dashboard.
  • Deleting plugins and themes from the dashboard.
  • Automatic background updates.

That's powerful, but it also means your site won't update itself. Only use it if you deploy code and updates another way, for example through Git and a CI pipeline, a managed WordPress host that handles updates, or regular WP-CLI updates run by you or a scheduled task.

For most sites, DISALLOW_FILE_EDIT alone is the right balance. If you use DISALLOW_FILE_MODS, make sure you have a reliable process for security updates, or you'll trade one risk for a bigger one.

Using a Must-Use Plugin Instead

If you can't edit wp-config.php (some managed hosts restrict it), you can achieve a similar effect with a must-use plugin. Create wp-content/mu-plugins/sajjad-disable-file-editor.php:

<?php
/**
 * Plugin Name: Sajjad Disable File Editor
 * Description: Removes the theme and plugin file editor capabilities for all users.
 */

add_filter( 'map_meta_cap', 'sajjad_block_file_editor_caps', 10, 2 );

function sajjad_block_file_editor_caps( $caps, $cap ) {
    if ( in_array( $cap, array( 'edit_themes', 'edit_plugins', 'edit_files' ), true ) ) {
        return array( 'do_not_allow' );
    }
    return $caps;
}

This maps the file editing capabilities to do_not_allow, which WordPress treats as a capability no user has. The editor menu items disappear and direct access to the editor URLs is blocked. Because it's a must-use plugin, it loads automatically and can't be deactivated from the Plugins screen, though anyone with file access could still remove it. The wp-config.php constant remains the preferred approach where you have access.

How to Verify File Editing Is Disabled

After making the change, confirm it works:

  • Check the menus: Log in as an administrator. The Theme File Editor should be gone from the Appearance or Tools menu, and the Plugin File Editor should be gone from the Plugins or Tools menu.

  • Try the URLs directly: Visit /wp-admin/theme-editor.php and /wp-admin/plugin-editor.php. You should see a message saying you're not allowed to edit templates or plugins for this site.

  • Check with WP-CLI: Confirm the capability is gone for your admin user:

wp user list --role=administrator --field=user_login
wp eval 'var_dump( user_can( 1, "edit_themes" ) );'

Replace 1 with your admin user's ID. The second command should output bool(false).

  • Check Site Health: Some security plugins and site audit tools report whether file editing is disabled.

How to Edit Files After Disabling the Editor

Disabling the dashboard editor doesn't mean you can never change code. It just moves changes to safer tools:

  • SFTP with a code editor: Download the file, edit it in an editor like VS Code, and upload it back. Keep a copy of the original.
  • Your host's file manager: Most control panels include a file editor that requires hosting-level login, which is usually protected separately.
  • Git-based deployment: Keep your child theme or custom plugin in a Git repository and deploy changes through your host's Git integration or a CI pipeline.
  • Staging sites: Many hosts offer one-click staging. Make and test changes there, then push to production.
  • Code snippet plugins: Tools like Code Snippets or WPCode let you add small PHP snippets with some safety features. Be aware that these plugins bring back a form of in-dashboard code execution, so they partly undo the benefit of disabling the editor. Restrict who can use them and protect admin accounts with two-factor authentication.

For CSS-only changes, use Appearance > Editor > Styles (block themes) or Appearance > Customize > Additional CSS (classic themes). These don't touch PHP files and aren't affected by DISALLOW_FILE_EDIT.

Troubleshooting

The editor still appears after adding the constant: Make sure the line is above require_once ABSPATH . 'wp-settings.php';, that you uploaded the file to the correct site, and that the value is true without quotes. Also check that the constant isn't defined twice with different values.

I see a white screen after editing wp-config.php: You likely introduced a syntax error, such as a missing semicolon or a curly quote pasted from a document. Restore your backup copy of the file, then add the line again carefully in a plain text editor.

A plugin says it needs the file editor: Very few legitimate plugins need the dashboard file editor to work. If one does, consider whether there's a safer alternative.

I need to re-enable the editor temporarily: Change the value to false or comment out the line, make your change, then set it back to true. A better approach is to make the change via SFTP instead.


FAQ: Disabling File Editing in WordPress

It removes the Theme File Editor and Plugin File Editor from the WordPress dashboard, so no user can edit theme or plugin PHP files from inside WordPress.

Add it to wp-config.php in your WordPress root folder, above the line that says That's all, stop editing. It must come before wp-settings.php is loaded.

No. It only affects the admin dashboard. Your site's front end, content, and functionality stay exactly the same.

Yes. DISALLOW_FILE_EDIT only removes the editors. Plugin, theme, and core updates continue to work. Only DISALLOW_FILE_MODS blocks updates.

DISALLOW_FILE_EDIT removes the code editors only. DISALLOW_FILE_MODS also blocks installing, updating, and deleting plugins and themes, and disables automatic updates.

No single setting does. It removes one easy path for attackers who get admin access, but you should also use strong passwords, two-factor authentication, and keep everything updated.

Yes. The Site Editor Styles panel and the Customizer's Additional CSS panel don't edit PHP files and keep working normally.


Conclusion

Disabling file editing in the WordPress dashboard is one of the simplest and most effective hardening steps you can take. A single line, define( 'DISALLOW_FILE_EDIT', true );, in wp-config.php removes the theme and plugin editors and closes a common path attackers use to turn a stolen admin password into malicious code running on your server.

It also nudges you toward a better workflow: editing files through SFTP, Git, or a staging site, where you have backups and room to test. If you want even stronger protection and have a reliable update process, consider DISALLOW_FILE_MODS too. Either way, combine it with strong authentication and regular updates, and your dashboard becomes a much less useful place for an intruder.

Share :

Related Posts

What are the best WordPress security plugins?

What are the best WordPress security plugins?

The best WordPress security plugins for most sites are Wordfence, Sucuri Security, Solid Security, MalCare, All-In-One Security (AIOS), Patchstack, a

Dive Deeper
What are the most common website security threats?

What are the most common website security threats?

The most common website security threats are vulnerable or outdated software, weak and stolen passwords, malware infections, injection attacks like S

Dive Deeper
What is the difference between posts and pages in WordPress?

What is the difference between posts and pages in WordPress?

The main difference between posts and pages in WordPress is that posts are timely, dated entries that appear in your blog feed, archives, and RSS fee

Dive Deeper