Skip to content

wp-config.php generator

Answer a few questions and get a complete wp-config.php, built in your browser from WordPress's own sample file.

Database

Your host gives you these four. Leave them empty and the file keeps WordPress's stand-ins, to fill in on the server.

Usually localhost. Your host says if it is something else.

Letters, numbers and underscores. On a site that is already installed, use the prefix it has.

Settings

Sets WP_HOME and WP_SITEURL, which then override the addresses saved in the dashboard.

Logging writes errors to wp-content/debug.log and keeps them off the page. Switch it off again when you have read them.

The most memory WordPress asks PHP for. Your host's own limit still applies.

Plugins and themes can read this and behave differently on a copy.

Nobody can then edit code from the dashboard, which also keeps an intruder from doing so.

Only if a scheduled job on the server calls wp-cron.php for it. Otherwise scheduled posts and updates stop.

wp-config.php
<?php
/**
 * The base configuration for WordPress
 *
 * @link https://developer.wordpress.org/advanced-administration/wordpress/wp-config/
 *
 * @package WordPress
 */

// ** Database settings - You can get this info from your web host ** //
/** The name of the database for WordPress */
define( 'DB_NAME', 'database_name_here' );

/** Database username */
define( 'DB_USER', 'username_here' );

/** Database password */
define( 'DB_PASSWORD', 'password_here' );

/** Database hostname */
define( 'DB_HOST', 'localhost' );

/** Database charset to use in creating database tables. */
define( 'DB_CHARSET', 'utf8mb4' );

/** The database collate type. Don't change this if in doubt. */
define( 'DB_COLLATE', '' );

/**#@+
 * Authentication unique keys and salts.
 *
 * You can change these at any point in time to invalidate all existing cookies.
 * This will force all users to have to log in again.
 */
define( 'AUTH_KEY',         'put your unique phrase here' );
define( 'SECURE_AUTH_KEY',  'put your unique phrase here' );
define( 'LOGGED_IN_KEY',    'put your unique phrase here' );
define( 'NONCE_KEY',        'put your unique phrase here' );
define( 'AUTH_SALT',        'put your unique phrase here' );
define( 'SECURE_AUTH_SALT', 'put your unique phrase here' );
define( 'LOGGED_IN_SALT',   'put your unique phrase here' );
define( 'NONCE_SALT',       'put your unique phrase here' );

/**#@-*/

/**
 * WordPress database table prefix.
 *
 * Only numbers, letters, and underscores please!
 */
$table_prefix = 'wp_';

/**
 * For developers: WordPress debugging mode.
 *
 * @link https://developer.wordpress.org/advanced-administration/debug/debug-wordpress/
 */
define( 'WP_DEBUG', false );

/* Add any custom values between this line and the "stop editing" line. */


/* That's all, stop editing! Happy publishing. */

/** Absolute path to the WordPress directory. */
if ( ! defined( 'ABSPATH' ) ) {
	define( 'ABSPATH', __DIR__ . '/' );
}

/** Sets up WordPress vars and included files. */
require_once ABSPATH . 'wp-settings.php';
Built in your browser.

What this file is

wp-config.php sits in the site's main folder and tells WordPress where its database is and how to behave. WordPress ships a sample, wp-config-sample.php. The file built here is that sample with your answers filled in, and with the settings you chose added in the place the sample marks for them.

How to use it

  1. Fill in what you know. Anything left empty keeps the sample's stand-in, which you can replace on the server.
  2. Save the file, or copy its text.
  3. Upload it to the folder that holds wp-load.php and the wp-admin folder.
  4. Open the site. A new install continues with WordPress's own setup screen.

On a site that is already running

Keep a copy of the file you have before you replace it, and carry three things over exactly:

  • The four database values. A wrong one shows an error establishing a database connection.
  • The table prefix. WordPress looks for its tables under that prefix, and with a different one it behaves as if it had never been installed.
  • Any lines a plugin or your host added to the old file.

New keys and salts are safe to use on a running site. They log everyone out, and nothing more.

What it does with what you type

The file is put together in your browser as you type. Nothing you enter here, the database password included, is sent to us or to anyone else. If you would rather not type a password into any web page, leave that field empty and put the password into the file on the server.

Common questions

Where do I find the database name, user and password?
In your hosting control panel, where databases are created. The name and the user are listed there. If you do not know the password, set a new one there and use that.
Do I have to turn on any of the settings?
No. With every setting left as it is, the file is WordPress's own sample with your database details and fresh keys, which is all a new site needs.
Why is the file editor switch there?
WordPress's dashboard can edit theme and plugin code. Turning that off means a mistake there cannot take the site down, and someone who gets into an administrator account cannot change code from the dashboard.
What does logging errors do?
It writes PHP errors to wp-content/debug.log and keeps them off the page, so you can see what is failing without showing visitors. Switch it off again afterwards and delete the log.

Stuck after changing the file?

Put the copy of the old file back first. If the site still will not load, tell us what you see and we reply with the cause and a fixed quote.

Get a free diagnosis