Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A standard WordPress installation has three essential directories—wp-admin, wp-content, and wp-includes—plus configuration and request-handling files in its root folder. Learn what each part does before editing, moving, or deleting anything: wp-content holds your site’s themes, plugins, uploads, and custom data, while wp-admin and wp-includes are WordPress core and should normally be replaced only during a controlled core update.

What folders are in a WordPress installation?

Open the directory that contains wp-config.php. A normal WordPress site also shows wp-admin, wp-content, and wp-includes. That combination identifies the installation’s core directory, although the site may be served from a subdirectory and the WordPress URL and Site Address URL may differ.

Folder or file Purpose Beginner rule
wp-admin/ PHP, JavaScript, CSS, and other files that power the dashboard and administration screens. Do not customize it directly; core updates replace it.
wp-content/ The site-added area: themes, plugins, media uploads, and directories created by plugins. Back it up and preserve it during core updates.
wp-includes/ Most WordPress core PHP, common APIs, and shared front-end and administrative JavaScript/CSS. Do not delete or edit it to fix a normal site problem.

Learn WordPress describes the boundary this way: “The wp-content directory contains any files that can be added to a default WordPress site.”

What is inside wp-content?

themes/

Each installed theme has its own directory. The active theme supplies templates, styles, scripts, and sometimes PHP logic. A child theme is the safer place for custom template or style changes because updating its parent theme can overwrite direct edits.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

plugins/

Each plugin normally occupies a separate directory. Plugin code can add settings, custom post types, scheduled tasks, and its own subdirectories. If the dashboard fails after a plugin change, investigate this folder rather than modifying wp-includes.

uploads/

Media uploaded through WordPress is commonly organized by year and month. The database records attachment information, while the actual image, video, or document files live here. Deleting files manually can leave broken media references.

Plugin-created folders

Backups, caches, logs, generated assets, and other plugin data may appear directly under wp-content. Their names and deletion rules vary; consult the plugin’s documentation before removing them.

Which WordPress files are in the root directory?

index.php

This is the usual front controller for a request. It loads wp-blog-header.php, which loads wp-load.php and then the configuration and WordPress bootstrap. Leave the file intact.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

wp-config.php

This is the main configuration file. It contains database name, user, password, host, table-prefix settings, debugging constants, and security salts. A bad edit can produce “Error establishing a database connection” or prevent WordPress from loading.

  • Back up the file and confirm a recovery method before editing.
  • Use a plain-text or code editor—not Microsoft Word or another word processor.
  • Treat database credentials and salts as secrets; do not paste them into public tickets or repositories.
  • Check the values against the hosting provider when diagnosing a database connection error.

For additional protection, a host can place wp-config.php one directory above the installation and restrict its read access, provided the server is configured to load it correctly.

.htaccess

On Apache, this hidden per-directory configuration file commonly contains WordPress rewrite rules for pretty permalinks. FTP clients and hosting file managers often hide dotfiles, so enable an option such as “show hidden files” when looking for it. The Permalinks screen can display the rules that need to be copied into .htaccess.

nginx does not use .htaccess; rewrite rules belong in the server configuration. Microsoft IIS uses web.config instead. A missing or incorrect rule set commonly causes front-end 404 errors.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Other request scripts

Files such as wp-login.php, xmlrpc.php, wp-cron.php, wp-activate.php, and wp-signup.php handle login, remote requests, scheduled tasks, activation, and multisite registration flows. Their unfamiliar names are not a reason to delete them.

Can I delete wp-includes or wp-admin?

No. They are core directories required by WordPress. Removing or selectively editing them can break both the dashboard and front end. If core files are suspected to be damaged, use a backup, maintenance or staging workflow, and a documented update or reinstall process instead of deleting individual files.

How should a manual WordPress core update handle folders?

  1. Make a tested backup of the database and files, and put the site into a maintenance or staging workflow.
  2. Download the matching WordPress package and verify that the target version is appropriate for the site.
  3. Replace the old wp-admin and wp-includes directories with the new ones.
  4. Replace the new loose core files in the installation root.
  5. Keep the existing wp-content directory and its site-specific contents. Do not overwrite customized themes or plugin data unintentionally.
  6. Complete the browser-based database upgrade if WordPress requests it, then test login, permalinks, forms, media, and the front end.

Ownership and permissions must allow the update process to read core files and write where required. As a general hardening boundary, files in the root, wp-admin, and wp-includes should normally be writable only by the owner. Some wp-content paths may need web-server write access for uploads, updates, or caches; grant only what the host and workflow require.

Where is wp-config.php and why can’t I see .htaccess?

Finding wp-config.php

Look in the directory containing wp-admin, wp-content, and wp-includes. Some installations deliberately keep the file one level above that directory. If you use a hosting panel, open the site’s document root rather than a personal home directory or an unrelated subdomain folder.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Finding .htaccess

Turn on hidden-file display in the hosting panel or FTP/SFTP client. If no file exists, confirm that the server is Apache, check the Permalinks screen for the required rules, and verify that the server permits directory overrides. On nginx or IIS, look for the server-specific configuration instead.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshooting by symptom

The dashboard broke after a change

Review the most recent plugin or theme change under wp-content. Disable a suspected plugin by renaming its directory only when you have an approved recovery plan, and avoid “fixing” the problem by editing core files.

Posts or pages return 404

Check the server type and rewrite configuration, confirm that .htaccess is visible and contains the correct rules on Apache, then save the Permalinks settings to flush rewrite rules when appropriate.

WordPress reports a database connection error

Open wp-config.php with a plain-text editor and compare the database name, username, password, host, and table prefix with the values supplied by the host. Check for accidental quotation-mark, whitespace, or punctuation changes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An update cannot write files

Check file ownership and permissions, available disk space, and whether security controls are blocking the updater. Preserve wp-content and replace only the core paths required by the update procedure.

Which files can you safely edit?

For most site changes, edit through WordPress or work in wp-content using a child theme, a custom plugin, or documented plugin settings. Avoid direct edits to wp-admin, wp-includes, and core root scripts because updates overwrite them and manual changes can create security and compatibility problems.

Direct edits to wp-config.php and server configuration files are appropriate only when a trusted procedure specifies the exact change. Use SFTP or a hosting panel for file access, shell tools when you understand the server, and always keep a rollback copy. The right workflow depends on access method, Apache/nginx/IIS configuration, permissions, and whether the change touches core or only wp-content.

Frequently Asked Questions

What is wp-content in WordPress?

It is the site-added directory containing themes, plugins, uploads, and plugin-created data. Preserve it during WordPress core updates.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I delete wp-includes?

No. It contains required WordPress core code and shared assets. Replace it only as part of a controlled core update or repair.

Why is .htaccess hidden?

Names beginning with a dot are hidden by many file managers and FTP clients. Enable hidden-file display, and remember that nginx and IIS use different server configuration methods.

Where is wp-config.php?

Usually in the directory containing wp-admin, wp-content, and wp-includes; some secure installations place it one level above.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.