Skip to main content
< All Topics
Print

Set FORCE_SSL_ADMIN to true

WARNING: Enabling this setting can interfere with administrator access if HTTPS is not working correctly for the login page or wp-admin. Confirm that the admin area already works correctly over HTTPS before saving the change.

Description of the control

This control sets the desired value of FORCE_SSL_ADMIN in the wp-config Hardening section of the Core Hardening page. It is presented as a single checkbox labeled Set FORCE_SSL_ADMIN to true.

Use this control when administrative access should be forced to use SSL through the FORCE_SSL_ADMIN constant in wp-config.php.

Procedure

  1. In WordPress admin, open Posture Management.
  2. Select Core Hardening.
  3. In the wp-config Hardening section, review the detected wp-config.php path and current file status.
  4. Click Check wp-config.php permissions if you need to verify writability.
  5. Select Set FORCE_SSL_ADMIN to true.
  6. Click Save changes.

Validation

After saving, reload Posture Management -> Core Hardening and confirm that Set FORCE_SSL_ADMIN to true remains selected.

Then verify that login and wp-admin continue to work correctly over HTTPS.

Table of Contents