Skip to content

.htaccess

.htaccess is a settings file the Apache web server reads from a website's own folder each time a page is requested. WordPress writes its permalink rules there. One line the server cannot read takes every page of the site down.

By
WP Ministry
Published

In short

  • .htaccess is read by Apache and LiteSpeed servers. nginx has no such file, and one left on an nginx server does nothing.
  • WordPress rewrites everything between "# BEGIN WordPress" and "# END WordPress". Put rules of your own outside those two lines.
  • Keep a copy before you change it. A single line the server cannot read turns every page into a 500 error.

.htaccess is a plain text file of instructions for the web server, kept in the same folder as the website's files. Apache, the server software, reads it each time a page or a file is requested and applies it to that folder and every folder below it. Apache's documentation calls it a distributed configuration file. It lets a site change how the server behaves without touching the server's main configuration.

WordPress uses it for one job of its own: permalinks. Its rules hand every address that is not a real file or folder to index.php, which is how example.com/about/ reaches WordPress at all.

Where you meet it

In the root of the installation, beside wp-config.php. The name begins with a period, which hides the file on a Linux server, so a file manager or FTP program may not list it until its option to show hidden files is on.

WordPress's part sits between two marker lines:

.htaccess
# BEGIN WordPress
# The directives (lines) between "BEGIN WordPress" and "END WordPress" are
# dynamically generated, and should only be modified via WordPress filters.
# Any changes to the directives between these markers will be overwritten.
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>
# END WordPress

WordPress replaces what is between the markers and keeps what is outside them, so rules of your own go outside. The .htaccess generator builds a complete file around this block.

Which servers read it:

  • Apache: yes, where the host allows it.
  • LiteSpeed Web Server: yes. It is designed to read Apache's .htaccess files.
  • OpenLiteSpeed: rewrite rules only, and only once loading them from .htaccess is switched on. Other directives are ignored, and a change takes effect after the server is restarted.
  • nginx: no. WordPress's documentation says nginx has no directory-level configuration file, and that WordPress cannot write its rules for you. They go in the server's own configuration: see the nginx server block generator.

What goes wrong

  • A line the server cannot read. One misspelled directive, or one the host does not permit, and every page answers 500. See how to fix the 500 Internal Server Error.
  • The WordPress block is missing, or the file is. The home page loads and every other page answers 404. See how to fix 404 errors on posts and pages that exist.
  • WordPress cannot write to the file. Under Settings, then Permalinks, it says "Your .htaccess file is not writable, so updating it automatically was not possible." and shows the rules to paste in by hand.
  • A rule turns visitors away. A rule that refuses more than it was meant to gives a 403 Forbidden error.
  • A redirect that never happens. A rewrite rule placed below WordPress's block does not get its turn. Redirects go above it: see how to set up redirects in WordPress.

How to look at yours

Go to Tools, then Site Health, open the Info tab and expand Server. The row named ".htaccess rules" reads "Your .htaccess file contains only core WordPress features." or "Custom rules have been added to your .htaccess file." The row "Web server" names the server software.

Common questions

Can I delete .htaccess?

Rename it instead, so that you keep a copy. With the file gone, the home page still loads and other pages answer 404. Go to Settings, then Permalinks, and WordPress writes a new file with its own block, if it is allowed to write in that folder. Rules that you or a plugin had added are not put back.

Why does my .htaccess keep changing?

WordPress rewrites its own block, and a plugin that uses the file rewrites the block between its own markers. Anything you typed between a pair of markers is replaced the next time that happens. Lines of your own belong outside every pair.

Does every WordPress site have one?

No. A site on nginx has none, and a site that uses the "Plain" permalink setting does not need WordPress's rules. On Apache and LiteSpeed, WordPress creates the file when you choose one of the other permalink structures, if it is allowed to write in the folder.

Not sure what is wrong?

Tell us what you see. We reply with the cause and a fixed quote, and the diagnosis is free.