Where tools run
In your browser
Sent to a server
Nothing you type
Sign-up needed
None
Share link settings
In the URL hash

.htaccess Generator

The .htaccess Generator writes a commented Apache 2.4 .htaccess with security rules, compression, browser caching, HTTPS redirects and a login IP allowlist, and keeps the standard WordPress permalink block intact.

Step by step

  1. Open the folder that contains wp-config.php and wp-content over SFTP or your host’s file manager. Turn on hidden files if you cannot see .htaccess.
  2. Download the current file as a backup. Keep any rules a plugin added outside the WordPress block.
  3. Pick your options. Leave Force HTTPS off until https:// loads your site without certificate warnings.
  4. Replace the contents of .htaccess with the output, and paste back any plugin rules you want to keep.
  5. Load the home page, a post, /wp-admin/ and the login page in a private window.

The WordPress block

Every file ends with the rewrite rules WordPress itself writes. They assume WordPress is installed in the web root; for a subdirectory install, keep the block WordPress writes under Settings, Permalinks.

.htaccess
# BEGIN WordPress
# The directives (lines) between "BEGIN WordPress" and "END WordPress" are
# dynamically generated, and should only be modified via WordPress filters.
# Any changes to the directives between these markers will be overwritten.
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
</IfModule>

# END WordPress

Common problems

  • A 500 error usually means one directive is not allowed by your host. Options -Indexes is the usual culprit; switch it off and ask your host.
  • Rules inside <IfModule> are skipped silently when the module is missing, so check that mod_rewrite, mod_headers, mod_expires and mod_deflate are enabled.
  • Behind Cloudflare or a load balancer, the login allowlist sees the proxy’s IP address. Keep FTP access ready in case you lock yourself out.
  • HSTS is cached by browsers for the whole max-age. If you later drop SSL, returning visitors cannot reach the site over HTTP until it expires.