wp-config.php
wp-config.php is the file that holds a WordPress site's own settings, starting with the database name, user and password. WordPress reads it at the start of every request, so one wrong character in it can take the whole site down.
- By
- WP Ministry
- Published
In short
- wp-config.php sits beside the wp-admin and wp-includes folders, or one folder above them. It is not in the WordPress download. Setup creates it.
- It holds the database password and the security keys. Keep a copy before you change it, and never send it to anyone you would not give the site to.
- Your own lines go above the line that reads "That's all, stop editing!". Below it, a setting arrives after WordPress has started.
wp-config.php is the file where a WordPress site keeps its own settings. WordPress's documentation calls it one of the most important files in an installation: it holds the base configuration, beginning with the details WordPress needs to reach its database. WordPress loads it at the start of every request, before any plugin or theme.
The file is not part of the WordPress download. Setup creates it from the answers you give, using wp-config-sample.php as its pattern.
Where you meet it
It sits in the root of the installation, beside the wp-admin and wp-includes folders. WordPress also looks one folder above that, and nowhere else. Open it through your host's file manager or over SFTP.
A file made by setup holds, in this order:
- The database settings:
DB_NAME,DB_USER,DB_PASSWORDandDB_HOST. - Eight security keys and salts. Changing them makes every login cookie invalid, so everyone has to log in again.
$table_prefix: the start of every database table's name.WP_DEBUG, set tofalse.- A line that reads
/* That's all, stop editing! Happy publishing. */. Older files end it with "Happy blogging." What follows that line starts WordPress.
Anything you add goes above the stop-editing line. That is where the lines for debug mode go, and the two that fix a site's address, WP_HOME and WP_SITEURL, covered in how to change your WordPress URL.
What goes wrong
- A wrong database name, user, password or host. Every page shows "Error establishing a database connection". See how to fix it.
- A typing mistake. The file is PHP, and PHP reads all of it or none of it. One missing semicolon or quote mark and every page, the dashboard included, answers with a 500 error, usually with nothing on screen. The server's error log names the file and a line. See how to fix a PHP syntax error.
- The file is missing. WordPress sends every visitor to its setup screen, at
/wp-admin/setup-config.php. Put the file back from a backup, or make a new one with the same database details and table prefix. - A setting that does nothing. A line added below the stop-editing line is read after WordPress has already started, which is too late.
- The wrong people can read it. Whoever reads this file has the database password. WordPress's hardening guide says only you and the web server should be able to read it, which generally means a permission of 400 or 440.
The wp-config.php generator builds a complete file from WordPress's own sample, in your browser.
How to look at yours
With WP-CLI, one command prints the full path of the file your site is using:
wp config pathCommon questions
Is it safe to edit wp-config.php?
Yes, if you keep a copy first. Download the file, change one thing, save, and load the site. If every page fails, upload the copy and the site is back as it was. WordPress's documentation gives the same advice: have a backup, and know how to restore it, before you change these settings.
Can I move wp-config.php out of the website's folder?
WordPress looks in one other place: the folder directly above the installation. Its hardening guide describes the move, and also records that people disagree about whether it helps, and that a move done carelessly may introduce serious vulnerabilities. Wherever the file is, the guide's advice on who can read it still applies.
What happens if I change the security keys?
Every existing login cookie stops working, so every user is logged out and has to log in again. Nothing else changes: no content, password or setting is touched. WordPress's sample file says the keys can be changed at any time for exactly this purpose. The salt and security key generator makes a fresh set.

