Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Directory browsing is controlled by the web server, not by a WordPress setting. On Apache, disable listings with Options -Indexes in the applicable server configuration or permitted .htaccess file. On Nginx, use autoindex off; in the configuration that handles the affected path; Nginx does not read WordPress .htaccess files. If you cannot edit the server configuration, ask your hosting provider or administrator to apply the change.

What directory browsing is—and what disabling it changes

A directory listing is a web-server-generated page showing filenames when a request maps to a directory, no usable index file is served, and listing is enabled. WordPress’s installation troubleshooting describes the symptom as seeing a directory listing rather than a web page. The behavior is controlled by the web server, so installing a WordPress plugin is not the primary fix.

Turning off listings prevents the server from generating that index of files. It does not make files private: a person who knows or guesses a public file’s URL may still be able to retrieve it. Use authorization or suitable storage controls for sensitive files.

Disable listings on Apache

For Apache, add this directive in the configuration scope covering the WordPress document root or the affected subdirectory:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Options -Indexes

Apache’s WordPress .htaccess and Apache guidance explains that the Indexes option produces a formatted listing when a directory URL has no file selected by DirectoryIndex. The minus sign removes that option from those currently in effect.

Using .htaccess

You can put the directive in the applicable .htaccess file only if the host allows the relevant override there. If adding it causes an internal server error, restore the previous file or remove the new line, then ask the host to check the directive permissions and configuration. Hosts can instead apply the directive in the main Apache or virtual-host configuration.

Avoid adding an unrelated, large security-plugin ruleset just to disable listings; its other directives may have separate compatibility and behavior implications.

Disable listings on Nginx

In the Nginx configuration that handles the affected path, ensure the effective configuration includes:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
autoindex off;

Nginx documents autoindex in its ngx_http_autoindex_module reference. The directive can be set in http, server, or location context, and its documented default is off. If listings remain visible, a more specific matching setting or another server in front of WordPress may be involved.

WordPress’s Nginx server guidance notes that Nginx has no directory-level configuration file equivalent to Apache’s .htaccess; server configuration is administered separately. Do not add an .htaccess rule for Nginx. If you do not control the Nginx configuration, ask your host or server administrator to make the change.

If the site root shows a listing instead of WordPress

A directory index and a directory listing are different mechanisms. The index setting selects a default file, while the listing option controls whether filenames are displayed when no usable index is served. Disabling listings alone does not guarantee a designed page at every directory URL; the request may instead return an error or an application response.

If the site root displays files rather than loading WordPress, check that the server selects WordPress’s index.php. WordPress’s installation troubleshooting guidance specifically recommends Apache’s DirectoryIndex index.php for a directory listing instead of a web page. Nginx uses its own index directive to select an index file, as explained in Learn WordPress’s WordPress and web servers lesson. Selecting an index file addresses the default page; it is conceptually separate from turning off listings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Find the server and configuration you need

The right setting depends on the server actually handling the public request and whether you can edit its effective configuration:

Situation Where to configure it Action Who may need to apply it
Apache with relevant overrides allowed Applicable .htaccess or server configuration Options -Indexes Site administrator or host, depending on override policy
Nginx Applicable http, server, or location configuration autoindex off; Server administrator or hosting provider
Site root lists files instead of loading WordPress Server index configuration Ensure the intended index file is selected, such as index.php on Apache Administrator or host

Some hosting stacks put Nginx in front of Apache or use a managed proxy. Editing .htaccess may therefore have no effect on the response visitors receive. WordPress notes that a response header indicating Nginx can reflect a reverse proxy in front of Apache, so a single header does not establish the full backend architecture. Ask the host which server handles the affected request.

Verify the change and troubleshoot remaining listings

  1. Choose a directory URL that has no index file. Testing only the homepage is not enough: WordPress may serve its front page even if a subdirectory can still generate a listing.
  2. Request that URL and inspect the response. The body should no longer contain a generated list of filenames. The result could be an error, a 403, a 404, or an application response depending on server and application configuration; a particular status code is not guaranteed.
  3. If Apache returns a server error, restore the prior .htaccess state and ask the host to validate the directive’s permissions and syntax or apply the setting in server configuration.
  4. If Nginx still shows files, ask the administrator to inspect the effective configuration for autoindex on in a matching or more-specific location and reload configuration through the host’s normal process.
  5. If the files themselves must be private, configure access control or move them to appropriately protected storage; disabling generated listings does not block direct access to public URLs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.