Get a free website with any plan

See how
WORDPRESS

Disabling the plugin and theme file editor

Last updated

IN SHORT

Disabling the WordPress file editor stops users from editing theme and plugin PHP files directly inside wp-admin. You do this by adding define('DISALLOW_FILE_EDIT', true); to your wp-config.php file using the Flashcloud portal File Manager. It removes the editor menus immediately, cutting off a primary attack path if an admin account gets compromised.

Add one line to wp-config.php: define('DISALLOW_FILE_EDIT', true);. This removes the Appearance > Theme File Editor and Plugins > Plugin File Editor screens entirely. It's a fast way to close off a common attack path: if someone gets into wp-admin through a stolen password or a session left open on a shared computer, they can't use the built-in editor to drop malicious PHP straight into a live theme or plugin.

Why this matters

The plugin and theme editors let any user with the right capability edit PHP files directly from the browser and save changes immediately, live, with no review step. That's convenient during development and dangerous in production. It's one of the first things attackers look for after a successful login, because it turns "logged into WordPress" into "arbitrary code execution on the server" in a couple of clicks. Disabling it doesn't fix a compromised password, but it removes one of the easiest ways to escalate that compromise into a backdoor.

Block the whole file editor

This is the recommended approach for most sites, since almost nobody edits theme or plugin code directly in wp-admin once a site is live.

  1. Open File Manager from your Flashcloud portal, or connect over FTP/SFTP.
  2. Find wp-config.php in your site's root directory.
  3. Add this line above the /* That's all, stop editing! */ comment:
define('DISALLOW_FILE_EDIT', true);

Save the file. The Theme File Editor and Plugin File Editor menu items disappear from wp-admin immediately, no restart needed. This constant also blocks plugin and theme installs/updates from the dashboard if you set DISALLOW_FILE_MODS instead. That's a bigger hammer; most sites just want the editor gone while keeping normal update flows working.

Turn off just the code editor, keep other admin capabilities

If you want a narrower change, some security plugins expose a toggle for this same constant through a settings screen instead of editing files directly. Under the hood it sets the same DISALLOW_FILE_EDIT constant; there's no real functional difference between the two approaches. It's purely about whether you're comfortable opening wp-config.php yourself.

One thing worth knowing: this constant is all-or-nothing for the built-in editor. It doesn't offer a way to allow file editing for one admin but not another. If you need selective access, that's a job for a role and capability plugin, not this constant.

What you're not protecting against

This change blocks one specific tool; it doesn't replace a real security posture. If your site still needs code-level changes, do them safely:

  • Test changes on a copy first. See using WordPress staging for the safe workflow.
  • Make sure you have a recent backup before any code or plugin change. See backing up your WordPress site.
  • Edit files properly over SFTP or through cPanel's File Manager, with a local copy and version control if you have one, rather than pasting code into a browser textarea.

Disabling the editor also won't help if the underlying WordPress core, a plugin, or a theme has a vulnerability that lets an attacker write files without ever touching wp-admin. That's a different problem, handled by keeping everything updated and by the malware scanning that runs on your hosting account.

If wp-admin is already showing signs of compromise

If you notice unfamiliar admin users, unexpected file changes, or a site that suddenly redirects visitors elsewhere, don't stop at disabling the file editor. Open a ticket from your Flashcloud portal (Support > New ticket) or start a live chat. A real person will help you assess the damage and can walk you through restoring from a clean backup if needed.

Common questions

Can I still update plugins after turning this off?

Yes. Disabling the file editor leaves normal plugin and theme updates working. You only lose the built-in code editor screens in wp-admin, unless you set DISALLOW_FILE_MODS instead.

Can I disable the code editor for only some admins?

No. The DISALLOW_FILE_EDIT rule is all-or-nothing across your whole site. If you want selective access for specific users, you must use a role and capability plugin.

Do I have to restart my server after editing wp-config.php?

No server restart is needed. The Theme File Editor and Plugin File Editor menus vanish from wp-admin immediately after you save wp-config.php.

Does this protect my site if a plugin has a security flaw?

No. This rule only blocks the browser editor inside wp-admin. It cannot stop an attacker from writing files if an unpatched plugin or theme contains an exploit.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.