WordPress includes a built-in file editor that allows administrators to modify theme and plugin files directly from the dashboard. While this feature can be convenient for making quick changes, it also presents a security risk.
If an unauthorized user gains access to your WordPress administrator account, they could use the built-in editor to modify website files, inject malicious code, or even take the website offline.
For this reason, it is recommended to disable file editing from the WordPress dashboard, especially on production websites.
Table of Contents
Disable the File Editor
To disable file editing, add the following line to your wp-config.php file:
define('DISALLOW_FILE_EDIT', true);
Once this setting is enabled, the following menu items will no longer be available in the WordPress administration panel:
- Appearance → Theme File Editor
- Plugins → Plugin File Editor
How to Edit wp-config.php
The wp-config.php file is located in the root directory of your WordPress installation.
By default, this is:
public_html
You can edit the file by:
- Connecting to your hosting account via FTP or SFTP.
- Navigating to your WordPress installation directory.
- Opening the
wp-config.phpfile in a text editor. - Adding the following line before:
/* That's all, stop editing! Happy publishing. */
define('DISALLOW_FILE_EDIT', true);
- Saving the file and uploading it back to the server if necessary.
Benefits of Disabling File Editing
Disabling the built-in file editor provides several security benefits:
- Prevents unauthorized modification of theme and plugin files.
- Reduces the impact of compromised administrator accounts.
- Helps protect against malware injections.
- Encourages safer file management through FTP, SFTP, or version control systems.
Summary
To improve the security of your WordPress website, disable the built-in file editor by adding the following line to your wp-config.php file:
define('DISALLOW_FILE_EDIT', true);
This prevents file modifications from the WordPress dashboard and helps protect your website against unauthorized changes.