{"id":9762,"date":"2026-06-06T15:59:00","date_gmt":"2026-06-06T13:59:00","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=9762"},"modified":"2026-06-06T15:59:01","modified_gmt":"2026-06-06T13:59:01","slug":"how-to-disable-file-editing-from-the-wordpress-dashboard","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-disable-file-editing-from-the-wordpress-dashboard\/","title":{"rendered":"How to Disable File Editing from the WordPress Dashboard"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">WordPress includes a built-in file editor that allows administrators to modify theme and plugin files directly from the dashboard. While this feature can be convenient for making quick changes, it also presents a security risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If an unauthorized user gains access to your WordPress administrator account, they could use the built-in editor to modify website files, inject malicious code, or even take the website offline.<\/p>\n\n\n\n<\/div>\n\n<div id=\"mybox-209424384\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">For this reason, it is recommended to disable file editing from the WordPress dashboard, especially on production websites.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-disable-file-editing-from-the-wordpress-dashboard\/#Disable_the_File_Editor\" >Disable the File Editor<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-disable-file-editing-from-the-wordpress-dashboard\/#How_to_Edit_wp-configphp\" >How to Edit wp-config.php<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-disable-file-editing-from-the-wordpress-dashboard\/#Benefits_of_Disabling_File_Editing\" >Benefits of Disabling File Editing<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-disable-file-editing-from-the-wordpress-dashboard\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Disable_the_File_Editor\"><\/span>Disable the File Editor<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To disable file editing, add the following line to your <code>wp-config.php<\/code> file:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>define('DISALLOW_FILE_EDIT', true);\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Once this setting is enabled, the following menu items will no longer be available in the WordPress administration panel:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Appearance \u2192 Theme File Editor<\/li>\n\n\n\n<li>Plugins \u2192 Plugin File Editor<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_Edit_wp-configphp\"><\/span>How to Edit wp-config.php<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The <code>wp-config.php<\/code> file is located in the root directory of your WordPress installation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By default, this is:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>public_html\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You can edit the file by:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Connecting to your hosting account via FTP or SFTP.<\/li>\n\n\n\n<li>Navigating to your WordPress installation directory.<\/li>\n\n\n\n<li>Opening the <code>wp-config.php<\/code> file in a text editor.<\/li>\n\n\n\n<li>Adding the following line before:<\/li>\n<\/ol>\n\n\n\n<pre class=\"wp-block-code\"><code>\/* That's all, stop editing! Happy publishing. *\/\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>define('DISALLOW_FILE_EDIT', true);\n<\/code><\/pre>\n\n\n\n<ol start=\"5\" class=\"wp-block-list\">\n<li>Saving the file and uploading it back to the server if necessary.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Benefits_of_Disabling_File_Editing\"><\/span>Benefits of Disabling File Editing<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Disabling the built-in file editor provides several security benefits:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Prevents unauthorized modification of theme and plugin files.<\/li>\n\n\n\n<li>Reduces the impact of compromised administrator accounts.<\/li>\n\n\n\n<li>Helps protect against malware injections.<\/li>\n\n\n\n<li>Encourages safer file management through FTP, SFTP, or version control systems.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">To improve the security of your WordPress website, disable the built-in file editor by adding the following line to your <code>wp-config.php<\/code> file:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>define('DISALLOW_FILE_EDIT', true);\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This prevents file modifications from the WordPress dashboard and helps protect your website against unauthorized changes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[58,125],"manual_kb_tag":[517,2179,2427,2796,3708,4857,4858,4859,429,471],"class_list":["post-9762","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-web-applications-cms","manualknowledgebasecat-websites","manual_kb_tag-hosting-account","manual_kb_tag-wordpress-config-file","manual_kb_tag-public-html","manual_kb_tag-wordpress-dashboard","manual_kb_tag-disable-file-editing","manual_kb_tag-file-editor","manual_kb_tag-theme-file-editor","manual_kb_tag-plugin-file-editor","manual_kb_tag-wordpress-security","manual_kb_tag-root-directory"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/9762","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/9762\/revisions"}],"predecessor-version":[{"id":9765,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/9762\/revisions\/9765"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=9762"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=9762"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=9762"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}