Get a free website with any plan

See how
CPANEL

Stopping folder listings (Indexes)

Last updated

IN SHORT

To stop visitors from seeing folder listings on Flashcloud, open cPanel and navigate to the Indexes tool under Advanced. Select the folder you want to protect and turn off directory indexing, or add an index.html or index.php file directly to the directory so Apache serves a page instead of your files.

If visiting a folder on your site shows a plain "Index of /foldername" page listing every file instead of your actual page, directory indexing is turned on and there's no index file cPanel can serve instead. Fix it in cPanel's Indexes tool (under Advanced) for that folder, or add an index.html / index.php file to the folder so it loads automatically.

Turn off indexing in cPanel

Log in to cPanel and open Indexes (under Advanced). Click through the folder tree to the directory you want to lock down, select it, and disable directory indexing. This turns off directory listing for that folder, so visitors no longer see a file list when no index file is present.

You can apply this per-folder. A common pattern is leaving your main site directory alone (it has an index.php or index.html already) and locking down subfolders that hold uploads, backups, or assets that were never meant to be browsed directly, like /images, /uploads, or /backup.

Do it manually with .htaccess

If you'd rather edit the file directly, open File Manager and navigate to the folder in question. Edit (or create) .htaccess there and add:

Options -Indexes

Save the file. If the file doesn't exist yet, dotfiles like .htaccess may not show by default in File Manager, so check its settings for an option to show hidden files.

Why this happens

Apache's default behavior, when a visitor requests a folder URL and no index.html, index.php, or similar file exists in it, is to list the folder's contents if the Indexes option is enabled. That's convenient on a dev server but a liability in production: it can expose file names, structure, and sometimes files you didn't intend to publish, like old config backups or unminified source.

The cleanest long-term fix is both: disable indexing so nothing is ever listed by accident, and make sure every public-facing folder has an index file so visitors land on real content instead.

Check your PHP settings while you're in there

If the folder in question runs a PHP application and you're also troubleshooting upload or file-size issues nearby, that's a separate setting: PHP limits like upload_max_filesize are controlled from cPanel's MultiPHP INI Editor under Software, not from Indexes.

When to contact support

If folders are still listing their contents after you disable indexing, or you're not sure which directories are safe to lock down without breaking your site, open a ticket from the portal. Support is real people, not a bot, and they can help troubleshoot further.

Common questions

Why is my site showing a list of files instead of a page?

Directory indexing is active and the folder lacks an index file like index.html or index.php. You can turn off indexing for that directory in cPanel or upload an index file so it loads automatically.

How do I turn off directory listings with .htaccess?

Add the line Options -Indexes to the .htaccess file in that folder. Use File Manager to edit the file, and check your settings to show hidden files if .htaccess is missing.

Why is my .htaccess file missing in File Manager?

Dotfiles are hidden by default in File Manager. Open File Manager settings and select the option to display hidden files.

Can I change my PHP upload size in the Indexes tool?

No, Indexes only manages folder listing permissions. You must use MultiPHP INI Editor under Software in cPanel to update upload_max_filesize.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.