Some files on your site should never be accessible from a browser, such as configuration files, environment files, and logs. The .htaccess file lets you block direct access to them on Apache-based cPanel hosting.
Block a Specific File
To deny access to a single sensitive file, add this to the .htaccess in your public_html folder:
<Files wp-config.php>
Require all denied
</Files>
Anyone requesting that file directly will receive a 403 Forbidden error.
Block Files by Type
To protect a group of file types at once:
<FilesMatch "\.(env|ini|log|sql|bak)$">
Require all denied
</FilesMatch>
This is useful for hiding environment files, backups, and database dumps in one rule.
Protect the .htaccess File Itself
Make sure .htaccess cannot be read either:
<Files .htaccess>
Require all denied
</Files>
Files Worth Protecting
| File | Why Hide It | | --- | --- | | wp-config.php | Contains database credentials | | .env | Holds secret keys | | .sql or .bak | May expose your data | | error logs | Can reveal site paths |
Verify the Block
- Try to open the file directly in your browser.
- Confirm you see a 403 Forbidden response.
- Check that your site still loads normally.
The best protection is to keep sensitive files outside the public web root entirely. When that is not possible, these .htaccess rules add a strong second line of defense.