October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk3 min

Should You Forbid PHP Execution in WordPress Directories?

Blocking PHP execution in wp-content/uploads is a common hardening measure. A restriction in wp-includes may also be available, but its safety depends on the hosting configuration and exceptions.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Block PHP execution in wp-content/uploads using a control supported by your host, but do not apply a blanket rule to wp-includes without checking compatibility. Some managed WordPress tools offer a restriction for wp-includes, while an Apache Toolkit example makes a specific TinyMCE exception. There is no single safe rule for every hosting stack.

Why block PHP execution in uploads?

The wp-content/uploads directory is intended for uploaded media, which normally has no reason to run as PHP. Preventing PHP files there from executing can reduce the risk that an uploaded executable file is invoked directly. Softaculous documents a security option that prevents PHP execution in this directory: Softaculous WordPress Manager Security Measures.

Use your hosting control panel’s supported security setting if one is available. A manual .htaccess rule is appropriate only when the server is configured to read that file and permits the directives it contains.

Should you also restrict PHP in wp-includes?

Not with an unreviewed, blanket rule. The answer in the original SitePoint discussion says WordPress relies on PHP scripts in wp-includes and advises against disabling PHP there. That is one forum participant’s advice, not a universal platform guarantee.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On the other hand, Softaculous documents a managed option that prevents PHP execution in wp-includes. A WordPress Toolkit hardening guide also gives an Apache-oriented example that blocks PHP requests in the directory while making an exception for wp-includes/js/tinymce/wp-tinymce.php. That example illustrates why rules may need exceptions; it does not establish that this exact exception is needed on every current WordPress site.

So, a carefully managed restriction may work in a particular environment, but the availability of a control or example does not make a custom blanket denial safe everywhere. Prefer the implementation your host supports and verify the site’s behavior afterward.

Choose a control that matches your hosting stack

Approach What to check Trade-off
Hosting or WordPress Toolkit security option Confirm which directory it affects, whether it adds exceptions, and how to reverse it. Softaculous documents options for both directories and says its security measures can be reverted if they make the site work incorrectly. Uses a provider-managed control, but the setting’s exact behavior depends on the tool and configuration.
Manual .htaccess rule Confirm the server is Apache-based, reads .htaccess for that directory, and allows the directives used. Review the rule’s scope and any needed exceptions. Offers direct control, but may be ignored or rejected by the server, or block files the site needs.
Nginx or another server configuration Ask the hosting provider or administrator for the supported server-native method. The cited Apache example does not provide universal instructions for Nginx or other stacks.

Server configuration determines whether .htaccess is honored and how PHP requests are routed. The available examples do not establish a one-size-fits-all directive for Apache, Nginx, PHP-FPM, or managed hosting. If you use a manual rule, follow documentation for your actual stack rather than copying an isolated snippet.

Apply the restriction and check for breakage

  1. Identify the server and control available. Check your hosting documentation or ask support whether the site uses Apache, Nginx, or another stack, and whether a managed WordPress security option is provided.
  2. Apply the narrowest supported setting. For uploads, restrict PHP execution in wp-content/uploads. For wp-includes, use only a host-supported or administrator-reviewed configuration, including any exceptions it requires.
  3. Test the public site and administration area. Open representative front-end pages and sign in to wp-admin. Check the features and pages your site actually uses for errors or missing functionality.
  4. Undo the specific change if behavior breaks. Use the control panel’s reversal option when available, or have the administrator remove or revise the rule. Softaculous says its security measures can be reverted if they make a site work incorrectly.

Toolkit settings are not interchangeable: cPanel separately documents that disabling admin script concatenation can cause Site Health inconsistencies. That is a different setting, not evidence that PHP restrictions in either directory cause the same issue. See cPanel’s explanation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the available evidence does—and does not—establish

Softaculous’s documentation, last modified May 14, 2026, describes managed PHP restrictions for both directories and says custom .htaccess directives may override its measures. The Toolkit example is Apache-oriented, and the SitePoint and Plesk discussions are forum reports rather than universal compatibility documentation. A Plesk forum discussion describes an individual Ubuntu 24.04/Plesk Obsidian 18.0.65 setup and suggests WP Toolkit; it does not prove the right configuration for other installations.

These sources support using a managed restriction where available, especially for uploads, and treating wp-includes as an environment-specific decision. They do not show that every PHP file in wp-includes can be denied safely, or that any single custom rule works across hosts.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.