Files and Paths Blocked for Security
To protect your sites, the server refuses some requests even when the file exists. Visitors get 403 Forbidden. Your own code can still read these files; only direct web access is blocked.
Always blocked
| What | Why |
|---|---|
Files and folders starting with a dot: .env, .git/, .htpasswd… | They hold settings and secrets. (/.well-known/ is allowed.) |
wp-config.php, configuration.php, config.inc.php | Database passwords |
composer.json, composer.lock, package.json | Reveal your software versions |
Files ending in .sql, .bak, .old, .orig, .save, .swp, .log, .ini, .sh | Backups, dumps and logs left in a web folder by accident |
PHP files inside uploads/, wp-content/uploads/, files/, images/, assets/, media/ | Stops a script uploaded through a vulnerable plugin from running |
Zip and tar archives are not blocked, so download links to them work.
Rate-limited
wp-login.phpandxmlrpc.php: about 20 requests a minute per visitor; more get 429 Too Many Requests. Repeated login attempts get the visitor's IP banned for an hour.
Things that don't apply here
.htaccessfiles are ignored. The server isn't Apache; rewrites for WordPress and most frameworks work without them (requests for missing files go toindex.php). If your app relies on special.htaccessrules, contact support.
Seeing a 403 you don't expect?
Check whether the file name or folder matches a rule above. A common case is a script in an images/ or uploads/ folder: move it to another folder. If you think a rule blocks something legitimate, contact support.