The WP-Config Generator builds a complete wp-config.php with database settings, fresh security salts, debugging, hardening and memory limits. Nothing you enter, including the database password, leaves the page.
Step by step
- Enter the database name, user, password and host your hosting panel gave you. Keep the table prefix as
wp_unless you have a reason to change it. - On the Security tab, choose the file-editing, HTTPS and core update rules to apply.
- On the Debugging tab, set the environment type. Turn on debug mode only while you are tracking down a problem.
- Adjust memory limits and revisions on the Performance tab, or clear a field to leave that constant out.
- Download the file and upload it to the folder that holds
wp-settings.php, or one level above it.
Example
A production site with the file editor disabled, HTTPS forced for the dashboard and revisions capped at 10 gets these lines, among others:
define( 'DB_NAME', 'acme_wp' );
define( 'DB_HOST', 'localhost' );
define( 'WP_ENVIRONMENT_TYPE', 'production' );
define( 'WP_DEBUG', false );
define( 'DISALLOW_FILE_EDIT', true );
define( 'FORCE_SSL_ADMIN', true );
define( 'WP_AUTO_UPDATE_CORE', 'minor' );
define( 'WP_MEMORY_LIMIT', '128M' );
define( 'WP_POST_REVISIONS', 10 );Before you upload
Never commit wp-config.php
Add it to .gitignore and keep a wp-config-sample.php without secrets in the repository instead. After uploading, set permissions to 440 or 400; some hosts need 600.
DB_HOSTis not alwayslocalhost. Managed hosts often use a hostname, a port such as127.0.0.1:3307or a socket path.DISALLOW_FILE_MODSalso blocks every update from the dashboard, including security updates. Use it only when deployments or WP-CLI handle updates.FORCE_SSL_ADMINon a site without a working certificate locks you out of the dashboard until you edit the file again.- Changing the table prefix on an existing site does not rename the tables.
