wp-config.php holds database credentials, secret keys, and increasingly, API keys for third-party services. It’s also, by default on a lot of hosts, sitting at file permissions that are looser than they need to be.
File permissions worth checking
chmod 600 wp-config.php # owner read/write only, if PHP-FPM runs as your user
chmod 644 wp-content/themes/*/*.php
chmod 755 wp-content/uploads
find wp-content/uploads -name "*.php" -delete # uploads folder should never execute PHP
That last one is worth taking seriously — an uploads directory that can execute PHP is a common path for a compromised site to end up with a backdoor, usually via a file upload form that didn’t check the actual file type, only the extension.
Moving wp-config.php up a directory
WordPress checks one level above the WordPress root automatically, so if your structure allows it:
/home/user/wp-config.php
/home/user/public_html/ (WordPress root, web-accessible)
This puts the file outside the web-accessible directory entirely, so even a misconfigured server can’t serve it directly as text.
Salts and keys
The eight security keys and salts in wp-config.php should be unique per site and regenerated if you ever suspect a compromise — WordPress’s own API generates a fresh set. Regenerating them invalidates all current login cookies, logging every session out, which is expected and fine.
Disabling file editing from wp-admin
define('DISALLOW_FILE_EDIT', true);
This removes the built-in theme/plugin editor from the admin panel. It doesn’t stop someone with FTP or SSH access, but it does mean that if an attacker only gets as far as a compromised admin login, they can’t use the file editor to drop a backdoor directly through the browser.