Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

On an Apache WordPress site, .htaccess is mainly the control file that enables pretty permalinks and directory-level behavior. The nine techniques below cover the safest, documented uses: restoring WordPress rewrites, understanding rule scope, redirecting to HTTPS, adding directory authentication, avoiding unsafe caching, and diagnosing ignored or broken directives. They apply only when Apache is configured to read .htaccess and permit the relevant directives.

Apache recommends putting configuration in the main server or virtual-host configuration when you control it, because .htaccess files add per-request filesystem and configuration work. See Apache’s .htaccess tutorial and WordPress’s Apache guidance.

Before editing .htaccess

  • Make a backup of the existing file and know how to restore it through your host’s file manager, SFTP or control panel.
  • Confirm the site is actually served by Apache or an Apache-compatible layer. Nginx-only hosting does not process .htaccess.
  • Ask the host whether the relevant directory permits overrides. Apache’s documented default for AllowOverride is None; AllowOverrideList can further restrict individual directives. See Apache’s .htaccess tutorial.
  • After every change, test both the front end and /wp-admin/. A syntax error can produce HTTP 500.

1. Restore WordPress’s standard permalink rules

When pretty permalinks stop working, the first repair is usually the standard WordPress rewrite block in the site’s document root. It sends requests that are not existing files or directories to index.php, where WordPress resolves the requested URL.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
# BEGIN WordPress
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteBase /
RewriteRule ^index.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>
# END WordPress

Use the block generated for your installation from WordPress’s Apache guidance. Do not overwrite host-specific rules, multisite rules or security directives without first saving a copy.

2. Let real files bypass the front controller

The condition RewriteCond %{REQUEST_FILENAME} !-f means an existing file—such as an image, stylesheet or JavaScript asset—is served directly instead of being routed through WordPress. Keep this condition in the standard block unless you have a documented reason to change asset handling.

3. Let real directories bypass the front controller

The companion condition RewriteCond %{REQUEST_FILENAME} !-d excludes existing directories from the catch-all rewrite. Together, the file and directory checks prevent the front controller from intercepting paths that Apache can serve directly.

4. Use the right pattern context in .htaccess

A rule copied from a virtual-host or main server configuration may fail in .htaccess. Apache removes the current directory prefix before matching a RewriteRule pattern in this context. In the document root, a request for /about/ is therefore matched as about/, not /about/.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Patterns in the root file normally omit the leading slash, as in RewriteRule . /index.php [L]. If you move a rule between server configuration and a per-directory file, re-check its pattern, substitution and rewrite base against Apache’s .htaccess tutorial.

5. Add the trailing slash to a multisite wp-admin URL

For the documented multisite configuration, WordPress includes a redirect that turns /wp-admin into /wp-admin/. This avoids an incorrect relative path when the administration directory is requested without its trailing slash.

RewriteRule ^wp-admin$ wp-admin/ [R=301,L]

Use this only with the matching multisite rewrite block from WordPress’s Apache guidance. A single-site installation or a different network layout may not need it.

6. Redirect HTTP requests to HTTPS when no server-level redirect is available

Apache prefers a virtual-host redirect for this job. Its rewrite fallback can be used in .htaccess when you cannot edit server configuration:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [END,NE,R=permanent]

This pattern comes from Apache’s redirecting and remapping guide. Confirm that TLS is valid for every hostname and that your proxy or load balancer sets HTTPS information correctly; otherwise, a redirect loop can result. Test with a temporary redirect strategy before committing a permanent redirect to production.

7. Protect a directory with Apache authentication

Apache can require a username and password for a directory when the host permits authentication directives in that directory’s override class. A typical protected-directory configuration is:

AuthType Basic
AuthName "Restricted area"
AuthBasicProvider file
AuthUserFile "/absolute/path/to/.htpasswd"
Require valid-user

Create the password file through your host’s approved method, keep it outside the publicly served directory when possible, and use an absolute path accepted by the host. Authentication directives require the appropriate AuthConfig permission; otherwise Apache may reject them. Basic authentication must be used with TLS so credentials are not exposed. See Apache’s authentication guide.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

8. Treat caching rules as unsafe for private responses

Do not add broad caching directives to a directory that serves personalized, authenticated or authorization-controlled responses without understanding the complete Apache cache configuration. Apache documents cases in which a cached entity can be served without traversing .htaccess again to re-check filesystem authorization. That can expose content or apply the wrong access decision.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Review Apache’s caching guide and your proxy or CDN behavior before caching protected WordPress pages, account areas or administration responses. Public, identical assets and private application responses require different cache policies.

9. Diagnose a .htaccess file that is ignored or causes errors

  1. Verify the file is named exactly .htaccess and is in the directory whose requests it should affect.
  2. Ask the host to confirm AllowOverride and AllowOverrideList permit the directives and that required modules, such as mod_rewrite, are loaded.
  3. Check Apache’s error log immediately after reproducing the problem. It can identify a forbidden directive, an unknown module directive or a syntax error.
  4. Test with one minimal change at a time. A malformed directive commonly returns HTTP 500; restore the backup to recover access, then reintroduce changes separately.
  5. Compare the rule’s pattern with its context. A pattern copied from server configuration may need its leading path removed in .htaccess.

If the host does not permit the required override class, the fix belongs in the virtual-host configuration or in a hosting plan that provides Apache-compatible WordPress controls.

What these tricks can—and cannot—do

These examples are Apache-specific and deployment-dependent. They do not establish universal recipes for compression, directory indexes, blocking individual WordPress files, XML-RPC, security headers or browser-expiry policies. Those features require their own module, version and hosting checks; adding unverified snippets can break a site or weaken its security.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.