CDNShark Documentation

Web Hosting

← Back to Documentation

Files and Paths Blocked for Security

To protect your sites, the server refuses some requests even when the file exists. Visitors get 403 Forbidden. Your own code can still read these files; only direct web access is blocked.

Always blocked

WhatWhy
Files and folders starting with a dot: .env, .git/, .htpasswd…They hold settings and secrets. (/.well-known/ is allowed.)
wp-config.php, configuration.php, config.inc.phpDatabase passwords
composer.json, composer.lock, package.jsonReveal your software versions
Files ending in .sql, .bak, .old, .orig, .save, .swp, .log, .ini, .shBackups, dumps and logs left in a web folder by accident
PHP files inside uploads/, wp-content/uploads/, files/, images/, assets/, media/Stops a script uploaded through a vulnerable plugin from running

Zip and tar archives are not blocked, so download links to them work.

Rate-limited

  • wp-login.php and xmlrpc.php: about 20 requests a minute per visitor; more get 429 Too Many Requests. Repeated login attempts get the visitor's IP banned for an hour.

Things that don't apply here

  • .htaccess files are ignored. The server isn't Apache; rewrites for WordPress and most frameworks work without them (requests for missing files go to index.php). If your app relies on special .htaccess rules, contact support.

Seeing a 403 you don't expect?

Check whether the file name or folder matches a rule above. A common case is a script in an images/ or uploads/ folder: move it to another folder. If you think a rule blocks something legitimate, contact support.