The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →To stop a web server from displaying an “Index of” file list, disable directory indexing on the server that serves your WordPress site. On Apache, use Options -Indexes in an applicable .htaccess file or server configuration. On Nginx, set autoindex off; in the matching server configuration. Nginx does not use WordPress’s .htaccess file, so its setting usually requires help from your host or server administrator.
What directory browsing is—and what turning it off does
A directory listing appears when a request points to a directory, the server does not serve a usable index file, and directory listing is enabled. Apache calls the option Indexes; Nginx provides the autoindex module. The listing is generated by the web server, not by a WordPress plugin. WordPress’s Apache guidance describes Apache’s listing behavior, and the Nginx autoindex module documentation explains the equivalent Nginx feature.
Disabling listings is different from choosing a default page. Apache’s DirectoryIndex and Nginx’s index directives determine which index file to serve. If no index file is available and listings are disabled, the request may show an error or another application response rather than a polished page. Learn WordPress’s web-server overview explains the distinction.
First identify the web server that handles the request
The correct setting depends on the effective server configuration, not simply on the fact that the site runs WordPress. A host may use Nginx, Apache, or a proxy in front of another server. WordPress notes that a response header may reflect a reverse proxy, so one header alone may not reveal the full setup. Check your hosting control panel or ask your provider which server handles the affected URL and whether you can edit its configuration.
#1 Best Overall
Disable directory listings on Apache
Use Options -Indexes
Add this directive in the configuration scope that covers the WordPress document root or the affected subdirectory:
Options -Indexes
The minus sign removes Indexes from the options currently in force. The directive can go in the applicable .htaccess file if the host permits that override, or in the Apache server or virtual-host configuration. WordPress’s Apache and .htaccess handbook documents the directive and how Apache uses .htaccess.
If the directive causes an error
If the site starts returning an internal server error after you edit .htaccess, restore the previous file or remove the new directive, then ask the host to check the syntax and whether that directive is allowed in .htaccess. The host can apply the setting in server configuration if overrides are not permitted. Avoid adding a large security-plugin ruleset just to change this one option; unrelated rules can have separate compatibility effects.
If the site root shows files instead of WordPress
A root URL displaying files instead of the site may indicate that Apache is not selecting WordPress’s index.php. That is an index-file configuration issue, not the same as enabling directory listings. WordPress’s installation guidance recommends checking for DirectoryIndex index.php for this symptom. Ask the administrator or host to correct the index selection as well as checking listing behavior.
Recommended Free Tools
Disable directory listings on Nginx
Set autoindex off; in the matching configuration
In the Nginx configuration that applies to the affected URL, ensure the relevant http, server, or location context contains:
autoindex off;
Nginx documents off as the default. If a listing remains visible, a more specific matching configuration may enable it, or another server or hosting layer may be serving the request. The Nginx module documentation describes the directive’s contexts and behavior.
Why editing .htaccess will not fix Nginx
Nginx does not read Apache-style .htaccess files. Its configuration is managed at server level, and WordPress cannot change it for you. If you do not administer the server, ask your hosting provider to inspect the effective configuration for the affected path and apply the setting. WordPress’s Nginx handbook explains this configuration model.
Which fix applies to your situation?
| Situation | Setting location | Action | Who may need to apply it |
|---|---|---|---|
| Apache with allowed overrides | Applicable .htaccess or server configuration |
Options -Indexes |
Site administrator or host, depending on override policy |
| Nginx | Matching http, server, or location configuration |
autoindex off; |
Server administrator or hosting provider |
| Site root shows a listing instead of loading WordPress | Index-file configuration for the server | Ensure the intended index file is selected; for Apache, check for index.php in DirectoryIndex |
Server administrator or hosting provider |
Verify the change on the affected path
-
Choose a directory URL that does not have an index file. Testing only the home page is not enough: WordPress may serve it normally even if a subdirectory still produces a listing.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy. -
Request that URL in a browser or with your usual site-checking method. Confirm that the response body no longer contains a generated list of filenames.
-
Check the outcome rather than expecting one particular status code. Depending on server and application configuration, the response may be an error, a 403, a 404, or an application response.
Troubleshoot a listing that remains visible
-
Apache: Confirm the directive is in a scope covering the requested directory. If
.htaccesschanges have no effect, the host may disallow the relevant override or the request may be handled by another server layer. -
Nginx: Ask the administrator to inspect the effective configuration for
autoindex onin a matching or more specific location. Do not try to solve an Nginx configuration issue by editing.htaccess.Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy. -
Either server: Confirm you are testing the directory where the listing appeared, not a different URL or the site’s root page.
Directory listing protection is not file privacy
These settings stop the server from generating a browsable list; they do not make files private. Someone who already knows or guesses a file URL may still be able to retrieve it. For sensitive files, use appropriate authorization or storage controls rather than relying on Options -Indexes or autoindex off;.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

