WordPress.org

Forums

wp-content/plugins - Open Access (5 posts)

  1. comanco
    Member
    Posted 9 years ago #

    Is it normal that anyone can browse directly to and download from the wp-content/plugins folder? Including content being listed by search engines?
    Version 2.1

  2. Samuel B

    Posted 9 years ago #

    To block directory listings on your site, drop this in the .htaccess in the root.
    IndexIgnore *
    All directories without an index.html or index.php will not be listed.

  3. comanco
    Member
    Posted 9 years ago #

    So it is normal to be able to put http://www.example/wp-content/plugins and view the contents of this folder?
    I did look at the htacess file and in part this is what I now have do I still add IndexIgnore *

    IndexIgnore .htaccess */.??* *~ *# */HEADER* */README* */_vti*

  4. Samuel B

    Posted 9 years ago #

    Almost all servers will list directories (WP or not) if no index file is there.
    Yes, you can add that right below what you have.

  5. comanco
    Member
    Posted 9 years ago #

    First Thank you very much for your help I placed it as suggested and the following is now what shows if that is not a concern I can leave it as is. I assume what is now viewable is because of the index.php in the wp-content folder.

    Index of /wp-content/themes
    Name Last modified Size Description
    -----------------------------------------------------------
    -----------------------------------------------------------

    Apache/1.3.37 Server at website.com Port 80

Topic Closed

This topic has been closed to new replies.

About this Topic