WP-Config Generator
Build a complete wp-config.php with database settings, fresh security salts, debugging, hardening and memory limits.
<?php
/**
* WordPress configuration.
*
* Keep this file out of version control and readable only by the web
* server user (for example chmod 440 or 400).
*
* @link https://developer.wordpress.org/advanced-administration/wordpress/wp-config/
*/
// ** Database settings ** //
define( 'DB_NAME', 'acme_wp' );
define( 'DB_USER', 'acme_wp_user' );
define( 'DB_PASSWORD', 'change-me' );
define( 'DB_HOST', 'localhost' );
define( 'DB_CHARSET', 'utf8mb4' );
define( 'DB_COLLATE', '' );
/**#@+
* Authentication unique keys and salts.
*
* Enable JavaScript on the generator page to fill these with unique random
* values, or replace them with a fresh set from
* https://api.wordpress.org/secret-key/1.1/salt/
* Never go live with the placeholder phrase.
*/
define( 'AUTH_KEY', 'put your unique phrase here' );
define( 'SECURE_AUTH_KEY', 'put your unique phrase here' );
define( 'LOGGED_IN_KEY', 'put your unique phrase here' );
define( 'NONCE_KEY', 'put your unique phrase here' );
define( 'AUTH_SALT', 'put your unique phrase here' );
define( 'SECURE_AUTH_SALT', 'put your unique phrase here' );
define( 'LOGGED_IN_SALT', 'put your unique phrase here' );
define( 'NONCE_SALT', 'put your unique phrase here' );
/**#@-*/
// ** Database table prefix ** //
$table_prefix = 'wp_';
// ** Environment and debugging ** //
define( 'WP_ENVIRONMENT_TYPE', 'production' );
define( 'WP_DEBUG', false );
// ** Security ** //
define( 'DISALLOW_FILE_EDIT', true );
define( 'FORCE_SSL_ADMIN', true );
define( 'WP_AUTO_UPDATE_CORE', 'minor' );
// ** Performance ** //
define( 'WP_MEMORY_LIMIT', '128M' );
define( 'WP_MAX_MEMORY_LIMIT', '256M' );
define( 'WP_POST_REVISIONS', 10 );
define( 'AUTOSAVE_INTERVAL', 60 );
define( 'EMPTY_TRASH_DAYS', 30 );
/* That's all, stop editing! Happy publishing. */
/** Absolute path to the WordPress directory. */
if ( ! defined( 'ABSPATH' ) ) {
define( 'ABSPATH', __DIR__ . '/' );
}
/** Sets up WordPress vars and included files. */
require_once ABSPATH . 'wp-settings.php';
Output is valid and updates as you type.
Fix the highlighted fields to update the output.
Fill in your database details, pick the hardening and debugging options you want, and get a complete wp-config.php ready to upload. The eight security keys and salts are generated in your browser with a cryptographic random source, so each visitor gets their own set. Nothing you enter, including the database password, leaves this page.
Best practices
Where the file lives, who can read it and what stays out of version control.
Lock down file permissions
440 or 400 let the web server read wp-config.php while blocking other users on the server. Some hosts need 600 when PHP runs as the file owner.Keep it above the web root
wp-config.php one directory above its root, so the file can sit outside the public web folder on hosts that allow it.Never commit it to Git
.gitignore and keep a wp-config-sample.php without secrets in the repository.How to use
- Enter the database name, user, password and host your hosting panel gave you. Keep the table prefix as
wp_unless you have a reason to change it. - Open the Security tab and choose which file-editing, HTTPS and core update rules to apply.
- On the Debugging tab, set the environment type. Turn on debug mode only while you are tracking down a problem.
- Adjust memory limits and revision settings on the Performance tab, or clear a field to leave that constant out.
- Download the file and upload it to the folder that holds
wp-settings.php, or one level above it.
Example
A production site with the file editor disabled, HTTPS forced for the dashboard and revisions capped at 10 gets these lines, among others:
define( 'DB_NAME', 'acme_wp' );
define( 'DB_HOST', 'localhost' );
define( 'WP_ENVIRONMENT_TYPE', 'production' );
define( 'WP_DEBUG', false );
define( 'DISALLOW_FILE_EDIT', true );
define( 'FORCE_SSL_ADMIN', true );
define( 'WP_AUTO_UPDATE_CORE', 'minor' );
define( 'WP_MEMORY_LIMIT', '128M' );
define( 'WP_POST_REVISIONS', 10 );
The salt lines are filled with random 64-character strings when JavaScript runs. If you see put your unique phrase here, replace those values before going live.
Pitfalls
- Never commit
wp-config.phpto Git. Add it to.gitignoreand keep awp-config-sample.phpwithout secrets in the repository instead. - Lock down the file after upload. Permissions of
440or400let the web server read it while blocking other users on the server; some hosts need600when PHP runs as the file owner. - Replacing the keys and salts on a live site signs out every logged-in user, because their cookies were signed with the old values. That is useful after a breach, but surprising on a busy store.
WP_DEBUG_DISPLAYmust stay off in production. Printed notices can reveal file paths and plugin names to visitors. This generator hides output and logs towp-content/debug.logwhen logging is on; delete that log once you are done, since it can be publicly reachable.DISALLOW_FILE_MODSblocks plugin and theme installs and also every update from the dashboard, including security updates. Use it only when deployments or WP-CLI handle updates.DB_HOSTis not alwayslocalhost. Managed hosts often give a hostname such asmysql.example-host.com, a port like127.0.0.1:3307, or a socket path such aslocalhost:/tmp/mysql.sock.- Changing the table prefix on an existing site does not rename the tables. The site will act like a fresh install until the tables and a few option and user meta keys are renamed as well.
FORCE_SSL_ADMINon a site without a working certificate locks you out of the dashboard until you edit the file again.
Compatibility
The generated file follows the layout of the wp-config-sample.php shipped with current WordPress releases and needs PHP 7.2 or newer for __DIR__ and the other syntax used. WP_ENVIRONMENT_TYPE needs WordPress 5.5 or later; older versions ignore it. utf8mb4 requires MySQL 5.5.3 or MariaDB 5.5 or later. The constants WP_MEMORY_LIMIT and WP_MAX_MEMORY_LIMIT cannot raise memory beyond what the host allows in php.ini.
If you prefer the command line, WP-CLI can write the same file with wp config create --dbname=acme_wp --dbuser=acme_wp_user --prompt=dbpass, then add constants with wp config set DISALLOW_FILE_EDIT true --raw.
Frequently asked questions
Common questions about wp-config.php, database settings and security keys.
Where does wp-config.php go?
wp-settings.php and the wp-admin folder. WordPress also looks one directory above the root, which keeps the file outside the public web folder on hosts that allow it.Are the generated salts safe to use?
crypto.getRandomValues() and are never sent anywhere. Each page load gives a different set, and the output stays the same while you change other options.How do I rotate my keys and salts?
define() lines in your existing file and save it. Every user, including you, has to log in again afterwards.Why is my database password shown in plain text?
change-me example is only a placeholder.