WP-Config Generator

Build a complete wp-config.php with database settings, fresh security salts, debugging, hardening and memory limits.

Enable JavaScript to customise; default output below.

Database

The MySQL or MariaDB database WordPress will use.

Everything stays in your browser. Nothing you type here is sent to a server.

Usually localhost. Some hosts give a hostname, a host:port pair or a socket path.

Changing it on an existing site breaks the site until the tables are renamed too.

More options Show
Database charset

utf8mb4 supports emoji and is the WordPress default.

Leave empty to let MySQL pick the collation for the charset.

Overrides the Site Address setting. Leave empty to keep the database value.

Where the WordPress core files live. Leave empty to keep the database value.

Live preview wp-config.php
<?php
/**
 * WordPress configuration.
 *
 * Keep this file out of version control and readable only by the web
 * server user (for example chmod 440 or 400).
 *
 * @link https://developer.wordpress.org/advanced-administration/wordpress/wp-config/
 */

// ** Database settings ** //
define( 'DB_NAME', 'acme_wp' );
define( 'DB_USER', 'acme_wp_user' );
define( 'DB_PASSWORD', 'change-me' );
define( 'DB_HOST', 'localhost' );
define( 'DB_CHARSET', 'utf8mb4' );
define( 'DB_COLLATE', '' );

/**#@+
 * Authentication unique keys and salts.
 *
 * Enable JavaScript on the generator page to fill these with unique random
 * values, or replace them with a fresh set from
 * https://api.wordpress.org/secret-key/1.1/salt/
 * Never go live with the placeholder phrase.
 */
define( 'AUTH_KEY', 'put your unique phrase here' );
define( 'SECURE_AUTH_KEY', 'put your unique phrase here' );
define( 'LOGGED_IN_KEY', 'put your unique phrase here' );
define( 'NONCE_KEY', 'put your unique phrase here' );
define( 'AUTH_SALT', 'put your unique phrase here' );
define( 'SECURE_AUTH_SALT', 'put your unique phrase here' );
define( 'LOGGED_IN_SALT', 'put your unique phrase here' );
define( 'NONCE_SALT', 'put your unique phrase here' );
/**#@-*/

// ** Database table prefix ** //
$table_prefix = 'wp_';

// ** Environment and debugging ** //
define( 'WP_ENVIRONMENT_TYPE', 'production' );
define( 'WP_DEBUG', false );

// ** Security ** //
define( 'DISALLOW_FILE_EDIT', true );
define( 'FORCE_SSL_ADMIN', true );
define( 'WP_AUTO_UPDATE_CORE', 'minor' );

// ** Performance ** //
define( 'WP_MEMORY_LIMIT', '128M' );
define( 'WP_MAX_MEMORY_LIMIT', '256M' );
define( 'WP_POST_REVISIONS', 10 );
define( 'AUTOSAVE_INTERVAL', 60 );
define( 'EMPTY_TRASH_DAYS', 30 );

/* That's all, stop editing! Happy publishing. */

/** Absolute path to the WordPress directory. */
if ( ! defined( 'ABSPATH' ) ) {
	define( 'ABSPATH', __DIR__ . '/' );
}

/** Sets up WordPress vars and included files. */
require_once ABSPATH . 'wp-settings.php';

Output is valid and updates as you type.

Fill in your database details, pick the hardening and debugging options you want, and get a complete wp-config.php ready to upload. The eight security keys and salts are generated in your browser with a cryptographic random source, so each visitor gets their own set. Nothing you enter, including the database password, leaves this page.

Best practices

Where the file lives, who can read it and what stays out of version control.

Lock down file permissions

Permissions of 440 or 400 let the web server read wp-config.php while blocking other users on the server. Some hosts need 600 when PHP runs as the file owner.

Keep it above the web root

WordPress also looks for wp-config.php one directory above its root, so the file can sit outside the public web folder on hosts that allow it.

Never commit it to Git

The file holds your database password and the keys and salts that sign login cookies. Add it to .gitignore and keep a wp-config-sample.php without secrets in the repository.

How to use

  1. Enter the database name, user, password and host your hosting panel gave you. Keep the table prefix as wp_ unless you have a reason to change it.
  2. Open the Security tab and choose which file-editing, HTTPS and core update rules to apply.
  3. On the Debugging tab, set the environment type. Turn on debug mode only while you are tracking down a problem.
  4. Adjust memory limits and revision settings on the Performance tab, or clear a field to leave that constant out.
  5. Download the file and upload it to the folder that holds wp-settings.php, or one level above it.

Example

A production site with the file editor disabled, HTTPS forced for the dashboard and revisions capped at 10 gets these lines, among others:

define( 'DB_NAME', 'acme_wp' );
define( 'DB_HOST', 'localhost' );
define( 'WP_ENVIRONMENT_TYPE', 'production' );
define( 'WP_DEBUG', false );
define( 'DISALLOW_FILE_EDIT', true );
define( 'FORCE_SSL_ADMIN', true );
define( 'WP_AUTO_UPDATE_CORE', 'minor' );
define( 'WP_MEMORY_LIMIT', '128M' );
define( 'WP_POST_REVISIONS', 10 );

The salt lines are filled with random 64-character strings when JavaScript runs. If you see put your unique phrase here, replace those values before going live.

Pitfalls

  • Never commit wp-config.php to Git. Add it to .gitignore and keep a wp-config-sample.php without secrets in the repository instead.
  • Lock down the file after upload. Permissions of 440 or 400 let the web server read it while blocking other users on the server; some hosts need 600 when PHP runs as the file owner.
  • Replacing the keys and salts on a live site signs out every logged-in user, because their cookies were signed with the old values. That is useful after a breach, but surprising on a busy store.
  • WP_DEBUG_DISPLAY must stay off in production. Printed notices can reveal file paths and plugin names to visitors. This generator hides output and logs to wp-content/debug.log when logging is on; delete that log once you are done, since it can be publicly reachable.
  • DISALLOW_FILE_MODS blocks plugin and theme installs and also every update from the dashboard, including security updates. Use it only when deployments or WP-CLI handle updates.
  • DB_HOST is not always localhost. Managed hosts often give a hostname such as mysql.example-host.com, a port like 127.0.0.1:3307, or a socket path such as localhost:/tmp/mysql.sock.
  • Changing the table prefix on an existing site does not rename the tables. The site will act like a fresh install until the tables and a few option and user meta keys are renamed as well.
  • FORCE_SSL_ADMIN on a site without a working certificate locks you out of the dashboard until you edit the file again.

Compatibility

The generated file follows the layout of the wp-config-sample.php shipped with current WordPress releases and needs PHP 7.2 or newer for __DIR__ and the other syntax used. WP_ENVIRONMENT_TYPE needs WordPress 5.5 or later; older versions ignore it. utf8mb4 requires MySQL 5.5.3 or MariaDB 5.5 or later. The constants WP_MEMORY_LIMIT and WP_MAX_MEMORY_LIMIT cannot raise memory beyond what the host allows in php.ini.

If you prefer the command line, WP-CLI can write the same file with wp config create --dbname=acme_wp --dbuser=acme_wp_user --prompt=dbpass, then add constants with wp config set DISALLOW_FILE_EDIT true --raw.

Frequently asked questions

Common questions about wp-config.php, database settings and security keys.

Where does wp-config.php go?
In the WordPress root, next to wp-settings.php and the wp-admin folder. WordPress also looks one directory above the root, which keeps the file outside the public web folder on hosts that allow it.
Are the generated salts safe to use?
Yes. They come from your browser’s crypto.getRandomValues() and are never sent anywhere. Each page load gives a different set, and the output stays the same while you change other options.
How do I rotate my keys and salts?
Generate a new set, replace the eight define() lines in your existing file and save it. Every user, including you, has to log in again afterwards.
Why is my database password shown in plain text?
So you can check it before copying. The value stays in this browser tab and is not stored or sent to a server. Use a strong, unique password in the real file; the change-me example is only a placeholder.
Should I set WP_HOME and WP_SITEURL?
Only when you need to fix a wrong address or move a site. Once defined, the matching fields under Settings, General become read-only, so leave them empty for normal installs.

From the people who built this tool

WP Adminify

The WordPress admin, rebuilt: a dashboard worth looking at, menu and column control, a real file manager and the login page your client sees.

See WP Adminify Free version on WordPress.org

Weekly drops

New tools, when there are new tools

One email when something worth using ships. No schedule to fill, so no filler.

Your address goes nowhere else, and one click unsubscribes.