wp-config.php holds your database credentials and secret keys. The wp-includes directory holds WordPress core code that never needs to be requested directly by a browser. Both are common targets. The fix is a few lines of .htaccess that block direct access, plus (optionally) a security plugin for anything the rules can't cover.
Block direct access with .htaccess
Open File Manager in cPanel and edit the .htaccess file in your site's document root (usually public_html, or the subfolder your domain points to). Add this block, ideally right after the WordPress rules that Softaculous or the WordPress plugin already inserted between # BEGIN WordPress and # END WordPress:
<files wp-config.php> order allow,deny deny from all </files> <IfModule mod_rewrite.c> RewriteEngine On RewriteRule ^wp-includes/[^/]+\.php$ - [F,L] RewriteRule ^wp-includes/js/tinymce/langs/.+\.php$ - [F,L] RewriteRule ^wp-includes/theme-compat/ - [F,L] </IfModule>
The first block returns a 403 for any request that tries to load wp-config.php directly. It won't affect WordPress itself, which reads the file at the PHP level, not over HTTP. The second block stops direct requests to PHP files inside wp-includes, with two carve-outs: tinymce/langs serves language files some editors call directly, and the rule pattern is scoped so it doesn't catch legitimate asset loads like wp-includes/js/ or wp-includes/css/.
Save the file and load a few pages on your site, plus wp-admin, to confirm nothing broke. Updates and staging operate at the filesystem level too, so they're unaffected by this rule.
Test it
Try loading https://yourdomain.com/wp-config.php and https://yourdomain.com/wp-includes/registration-functions.php directly in a browser. Both should return a 403 Forbidden. If either loads normally, double check the .htaccess edit saved and that you're editing the right domain's document root, not a different addon domain or subdomain folder.
Move wp-config.php up a directory (optional, more disruptive)
WordPress checks one directory above the WordPress install for wp-config.php before it checks the install directory itself. On a single-site account, moving wp-config.php from public_html to the home directory above it takes the file outside the web-accessible tree entirely, though the exact layout can vary by account. Skip it if you're running WordPress out of a subdirectory alongside other sites, or if the layout would confuse a future migration.
When a plugin makes sense
The rules above cover the two specific files most worth hardening without adding overhead to every request. If you want broader protection, file integrity monitoring, and login hardening in one place, Imunify360 already runs a web application firewall on your account and is worth checking before adding another security plugin on top of it. If you decide you also want plugin-level hardening (login attempt limits, file change alerts inside wp-admin), keep it to one plugin. Stacking two full security suites adds overhead for no real gain and is one of the common causes covered in My WordPress site is slow.
Test changes on staging first
If you're not sure how a hardening plugin or a stricter rule set will interact with your theme or other plugins, try it on a staging copy before touching the live site. See Using WordPress staging for the workflow. This matters more if you run WooCommerce, since a rule that's too aggressive can silently break checkout, see Running a WooCommerce store for store-specific testing steps.
Back up before you touch .htaccess
A malformed .htaccess rule can return a 500 error site-wide instead of quietly failing, so keep a copy of the original file before you edit it. Flashcloud runs nightly backups, so you have a recent restore point if something goes wrong.
If something breaks
If a page starts returning a 403 that shouldn't, or wp-admin stops loading correctly, revert the .htaccess edit and test again in isolation. If the site is fully down and you can't get back in through File Manager, open a ticket from the portal (Support → New ticket). It goes to a real person, not a bot, and they can help you recover access.