Get a free website with any plan

See how
WORDPRESS

Blocking PHP execution in the uploads folder

Last updated

IN SHORT

Blocking PHP execution in the WordPress uploads folder stops malicious scripts from running if an attacker uploads a bad file. On Flashcloud, you can enable this hardening rule through a security plugin or by adding an .htaccess file directly inside wp-content/uploads. The server returns a 403 error for PHP requests without breaking normal media.

WordPress should never execute PHP files inside wp-content/uploads. That folder holds images, PDFs, and other media, never code, so blocking PHP execution there closes off a common attack path without touching how your site works day to day.

Why this matters

File upload forms are a favorite target. If an attacker finds a way to drop a PHP file into your uploads folder, whether through a vulnerable plugin, a compromised admin account, or a sloppy import tool, and that folder allows PHP execution, the attacker's script runs. That's how a single bad upload turns into a full site compromise: backdoors, spam injection, malware distribution, the works.

Blocking execution doesn't stop the bad file from being uploaded. It stops the server from running it as code. The file just sits there as inert data, harmless.

Check whether you're already covered

Flashcloud hosting runs Imunify360 as a web application firewall at the server level, so many attempts are already blocked before they reach your files. Adding the rule below closes the gap further.

Option 1: a WordPress security plugin

One option for most site owners is a security plugin that includes this as a built-in hardening option. Open wp-admin → Plugins and check whether your existing security plugin (Wordfence, iThemes Security, or similar) has a "disable PHP execution in uploads" or "prevent PHP execution in upload directories" toggle under its hardening or firewall settings. If it does, flip it on and you're done. No file editing required.

If you're not running a security plugin and don't want to add one just for this, use Option 2 instead.

Option 2: add an .htaccess rule

Flashcloud's hosting uses LiteSpeed Web Server, which reads standard .htaccess directives for Apache compatibility. Add an .htaccess file inside the uploads folder to block PHP execution there.

  1. Open File Manager from your portal service page, or connect with an FTP client.
  2. Navigate to wp-content/uploads.
  3. Create a new file named .htaccess in that folder if one doesn't already exist there.
  4. Add these lines:
<FilesMatch "\.(?i:php)$">
    Require all denied
</FilesMatch>

Save the file. Any request for a .php file inside uploads now returns a 403 error instead of executing. Test it by uploading a harmless test PHP file (a single line like <?php echo "test"; ?>) and requesting its URL directly in a browser. You should get a 403, not the "test" output.

This rule only affects the uploads folder. It won't touch your theme or plugin files elsewhere in the install, so normal WordPress operation is unaffected.

Test on staging first if you're unsure

Some page builders and gallery plugins generate helper files inside uploads subfolders that could, in rare cases, need to execute. This is uncommon, but if your site relies on unusual upload-processing plugins, apply the rule on a staging copy first and click through your media-heavy pages before pushing it live. See Using WordPress staging for the workflow. On a store, test uploads used for product images too. See Running a WooCommerce store for more on keeping a store site stable through changes.

When to contact support

If you find PHP files in your uploads folder that you didn't put there, that's an active compromise, not routine maintenance. Open a ticket from Support → New ticket in the portal. Real humans handle these and can walk you through next steps.

Common questions

Will blocking PHP in uploads break my images?

No, your media will continue to display normally. The uploads folder is meant for files like images and PDFs, so blocking PHP execution only targets executable code while leaving media untouched.

Does blocking PHP execution stop files from being uploaded?

No, it does not stop uploads from occurring. It prevents the server from executing uploaded files as code, leaving malicious files inert and returning a 403 error if accessed.

Does Flashcloud already protect my uploads folder?

Flashcloud servers block many attacks automatically using Imunify360 as a web application firewall. Adding this .htaccess rule inside your uploads directory closes the gap further by stopping any bypassed PHP files from executing.

What should I do if I find PHP files in uploads?

Open a ticket from the portal support page immediately. Unknown PHP files in your uploads folder indicate an active compromise, and Flashcloud support staff can help you handle next steps.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.