If you want to prevent visitors from seeing a list of files inside a directory on your website, you can disable directory listing using a rule in the .htaccess file.
This is useful for improving security and preventing exposure of sensitive files.
Table of Contents
What is directory listing?
By default, if a directory does not contain an index file (like index.php or index.html), the server may display a list of all files inside that folder. This can expose internal files and structure.
How to disable directory listing
To turn off directory listing, add the following rule to your .htaccess file:
Options -Indexes Where to add this rule
- Open your website files via FTP
- Locate the
.htaccessfile in your WordPress root directory - Add the rule at the end of the file
- Save the changes
How it works
Once enabled:
- Users will no longer see file listings in empty directories
- Accessing a folder without an index file will return a “403 Forbidden” or similar error
- Directory structure and file names are hidden from public view
Important notes
- This rule affects the entire directory where it is placed and all subdirectories
- WordPress already uses this rule in many default
.htaccessconfigurations - It is a lightweight and recommended security practice for most websites
Summary
Adding Options -Indexes to your .htaccess file is a simple and effective way to prevent directory browsing and improve the security of your WordPress installation.