How to Hide Sensitive Files with .htaccess

Use .htaccess rules to block public access to configuration files, logs, and other sensitive data on your cPanel site.

· Updated · 1,723 views

Some files on your site should never be accessible from a browser, such as configuration files, environment files, and logs. The .htaccess file lets you block direct access to them on Apache-based cPanel hosting.

Block a Specific File

To deny access to a single sensitive file, add this to the .htaccess in your public_html folder:

<Files wp-config.php>
    Require all denied
</Files>

Anyone requesting that file directly will receive a 403 Forbidden error.

Block Files by Type

To protect a group of file types at once:

<FilesMatch "\.(env|ini|log|sql|bak)$">
    Require all denied
</FilesMatch>

This is useful for hiding environment files, backups, and database dumps in one rule.

Protect the .htaccess File Itself

Make sure .htaccess cannot be read either:

<Files .htaccess>
    Require all denied
</Files>

Files Worth Protecting

| File | Why Hide It | | --- | --- | | wp-config.php | Contains database credentials | | .env | Holds secret keys | | .sql or .bak | May expose your data | | error logs | Can reveal site paths |

Verify the Block

  1. Try to open the file directly in your browser.
  2. Confirm you see a 403 Forbidden response.
  3. Check that your site still loads normally.

The best protection is to keep sensitive files outside the public web root entirely. When that is not possible, these .htaccess rules add a strong second line of defense.

Was this article helpful?

Your feedback helps us improve our documentation.

Still Need Help?

Our support team is available 24/7 to assist you.