Visitors can see folder contents if no index file is present.
Directory Browsing Enabled
Key Points: Anyone can see your site’s folders if directory listing is allowed on your server.
Navigate to /wp-content/uploads/ and see a list of images? That’s bad. Directory browsing reveals file names, structure, and sensitive breadcrumbs.
👀 Why It Matters
- Attackers scan for backup files, old zips, or install scripts
- Reveals plugin and theme paths
- Exposes personal data if poorly stored
🛠️ How to Disable It
- Add this line to your
.htaccessfile:Options -Indexes - Ensure all sensitive folders have
index.phpor redirect - Ask your host to disable directory listings server-wide
🚫 Reminder
Just because your files aren’t meant to be seen, doesn’t mean they’re hidden. Hide them properly.