Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To stop a web server from displaying an “Index of” file list, disable directory indexing on the server that serves your WordPress site. On Apache, use Options -Indexes in an applicable .htaccess file or server configuration. On Nginx, set autoindex off; in the matching server configuration. Nginx does not use WordPress’s .htaccess file, so its setting usually requires help from your host or server administrator.

What directory browsing is—and what turning it off does

A directory listing appears when a request points to a directory, the server does not serve a usable index file, and directory listing is enabled. Apache calls the option Indexes; Nginx provides the autoindex module. The listing is generated by the web server, not by a WordPress plugin. WordPress’s Apache guidance describes Apache’s listing behavior, and the Nginx autoindex module documentation explains the equivalent Nginx feature.

Disabling listings is different from choosing a default page. Apache’s DirectoryIndex and Nginx’s index directives determine which index file to serve. If no index file is available and listings are disabled, the request may show an error or another application response rather than a polished page. Learn WordPress’s web-server overview explains the distinction.

First identify the web server that handles the request

The correct setting depends on the effective server configuration, not simply on the fact that the site runs WordPress. A host may use Nginx, Apache, or a proxy in front of another server. WordPress notes that a response header may reflect a reverse proxy, so one header alone may not reveal the full setup. Check your hosting control panel or ask your provider which server handles the affected URL and whether you can edit its configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Disable directory listings on Apache

Use Options -Indexes

Add this directive in the configuration scope that covers the WordPress document root or the affected subdirectory:

Options -Indexes

The minus sign removes Indexes from the options currently in force. The directive can go in the applicable .htaccess file if the host permits that override, or in the Apache server or virtual-host configuration. WordPress’s Apache and .htaccess handbook documents the directive and how Apache uses .htaccess.

If the directive causes an error

If the site starts returning an internal server error after you edit .htaccess, restore the previous file or remove the new directive, then ask the host to check the syntax and whether that directive is allowed in .htaccess. The host can apply the setting in server configuration if overrides are not permitted. Avoid adding a large security-plugin ruleset just to change this one option; unrelated rules can have separate compatibility effects.

If the site root shows files instead of WordPress

A root URL displaying files instead of the site may indicate that Apache is not selecting WordPress’s index.php. That is an index-file configuration issue, not the same as enabling directory listings. WordPress’s installation guidance recommends checking for DirectoryIndex index.php for this symptom. Ask the administrator or host to correct the index selection as well as checking listing behavior.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Disable directory listings on Nginx

Set autoindex off; in the matching configuration

In the Nginx configuration that applies to the affected URL, ensure the relevant http, server, or location context contains:

autoindex off;

Nginx documents off as the default. If a listing remains visible, a more specific matching configuration may enable it, or another server or hosting layer may be serving the request. The Nginx module documentation describes the directive’s contexts and behavior.

Why editing .htaccess will not fix Nginx

Nginx does not read Apache-style .htaccess files. Its configuration is managed at server level, and WordPress cannot change it for you. If you do not administer the server, ask your hosting provider to inspect the effective configuration for the affected path and apply the setting. WordPress’s Nginx handbook explains this configuration model.

Which fix applies to your situation?

Situation Setting location Action Who may need to apply it
Apache with allowed overrides Applicable .htaccess or server configuration Options -Indexes Site administrator or host, depending on override policy
Nginx Matching http, server, or location configuration autoindex off; Server administrator or hosting provider
Site root shows a listing instead of loading WordPress Index-file configuration for the server Ensure the intended index file is selected; for Apache, check for index.php in DirectoryIndex Server administrator or hosting provider

Verify the change on the affected path

  1. Choose a directory URL that does not have an index file. Testing only the home page is not enough: WordPress may serve it normally even if a subdirectory still produces a listing.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  2. Request that URL in a browser or with your usual site-checking method. Confirm that the response body no longer contains a generated list of filenames.

  3. Check the outcome rather than expecting one particular status code. Depending on server and application configuration, the response may be an error, a 403, a 404, or an application response.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot a listing that remains visible

Directory listing protection is not file privacy

These settings stop the server from generating a browsable list; they do not make files private. Someone who already knows or guesses a file URL may still be able to retrieve it. For sensitive files, use appropriate authorization or storage controls rather than relying on Options -Indexes or autoindex off;.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.