Ideas

Idea: Stop directory listing by default

  1. Currently, a default installation of WordPress allows the /wp-content/plugins/ and /wp-content/themes/ folders to be listed in the web browser.

    Please could WordPress include a blank index.html file in these and other affected folders by default? It could help prevent malicious visitors discovering and exploiting plugins and themes that are known to be vulnerable.

    Posted: 1 year ago #
  2. RogueHand
    Member

    Just makes good sense. Otherwise it's like buying a new car without seat belts.

    Posted: 11 months ago #

RSS feed for this topic

Reply

You must log in to post.

Average Rating

(8)

Your Rating

This idea is under consideration.