Add one line to wp-config.php: define('DISALLOW_FILE_EDIT', true);. This removes the Appearance > Theme File Editor and Plugins > Plugin File Editor screens entirely. It's a fast way to close off a common attack path: if someone gets into wp-admin through a stolen password or a session left open on a shared computer, they can't use the built-in editor to drop malicious PHP straight into a live theme or plugin.
Why this matters
The plugin and theme editors let any user with the right capability edit PHP files directly from the browser and save changes immediately, live, with no review step. That's convenient during development and dangerous in production. It's one of the first things attackers look for after a successful login, because it turns "logged into WordPress" into "arbitrary code execution on the server" in a couple of clicks. Disabling it doesn't fix a compromised password, but it removes one of the easiest ways to escalate that compromise into a backdoor.
Block the whole file editor
This is the recommended approach for most sites, since almost nobody edits theme or plugin code directly in wp-admin once a site is live.
- Open File Manager from your Flashcloud portal, or connect over FTP/SFTP.
- Find
wp-config.phpin your site's root directory. - Add this line above the
/* That's all, stop editing! */comment:
define('DISALLOW_FILE_EDIT', true);
Save the file. The Theme File Editor and Plugin File Editor menu items disappear from wp-admin immediately, no restart needed. This constant also blocks plugin and theme installs/updates from the dashboard if you set DISALLOW_FILE_MODS instead. That's a bigger hammer; most sites just want the editor gone while keeping normal update flows working.
Turn off just the code editor, keep other admin capabilities
If you want a narrower change, some security plugins expose a toggle for this same constant through a settings screen instead of editing files directly. Under the hood it sets the same DISALLOW_FILE_EDIT constant; there's no real functional difference between the two approaches. It's purely about whether you're comfortable opening wp-config.php yourself.
One thing worth knowing: this constant is all-or-nothing for the built-in editor. It doesn't offer a way to allow file editing for one admin but not another. If you need selective access, that's a job for a role and capability plugin, not this constant.
What you're not protecting against
This change blocks one specific tool; it doesn't replace a real security posture. If your site still needs code-level changes, do them safely:
- Test changes on a copy first. See using WordPress staging for the safe workflow.
- Make sure you have a recent backup before any code or plugin change. See backing up your WordPress site.
- Edit files properly over SFTP or through cPanel's File Manager, with a local copy and version control if you have one, rather than pasting code into a browser textarea.
Disabling the editor also won't help if the underlying WordPress core, a plugin, or a theme has a vulnerability that lets an attacker write files without ever touching wp-admin. That's a different problem, handled by keeping everything updated and by the malware scanning that runs on your hosting account.
If wp-admin is already showing signs of compromise
If you notice unfamiliar admin users, unexpected file changes, or a site that suddenly redirects visitors elsewhere, don't stop at disabling the file editor. Open a ticket from your Flashcloud portal (Support > New ticket) or start a live chat. A real person will help you assess the damage and can walk you through restoring from a clean backup if needed.