Skip to main content
< All Topics
Print

Disable theme/plugin file editor

WARNING: Enabling this setting removes access to the built-in plugin and theme editor in WordPress admin. Confirm that administrators do not rely on the editor for emergency changes before enabling it.

Description of the control

This control appears in the Core File Permissions section as Disable theme/plugin file editor. Its enforcement option is the checkbox labeled Enforce DISALLOW_FILE_EDIT via a must-use plugin.

Use this control when the built-in WordPress file editor should be disabled on the site. The help text states that this is recommended on production sites.

Procedure

  1. In WordPress admin, open Posture Management.
  2. Select Core Hardening.
  3. In the Core File Permissions section, locate Disable theme/plugin file editor.
  4. Select Enforce DISALLOW_FILE_EDIT via a must-use plugin.
  5. Click Save changes.

Validation

After saving, reload Posture Management -> Core Hardening and confirm the checkbox remains selected.

Then verify that the built-in plugin and theme editor is no longer available in WordPress admin.

Table of Contents