↑ ↓ select, Enter open, Esc close

Secure the permissions of wp-config.php

Caution: This command changes the system. Understand what it does before you run it.

Adjust the values, the command updates live
user@server
chmod 600 /var/www/vhosts/example.com/httpdocs/wp-config.php

Removes all permissions on wp-config.php for group and others. This works when PHP runs as the file owner, as with Plesk using PHP-FPM or FastCGI, where PHP runs under the subscription user. Afterwards, load the site and check that it still works.

Note: If PHP runs as a different user, for example as an Apache module, a database error appears after setting 600. In that case use 640 with the appropriate group.

Open question before approval: Prüfen, ob 600 bei allen PHP-Handlern in Plesk Obsidian (FPM über Apache, FPM über nginx, FastCGI) zuverlässig funktioniert.

Also searched as

  • correct wp-config.php permissions
  • protect wp-config
  • secure wordpress database password
  • wp-config 600 or 640

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.