wp-config.php is the file that tells WordPress which database to connect to, and with what password. Without it, WordPress shows the installation screen, as though the site had never existed. Rebuilding it is a ten minute job, as long as you do things in this order.
You need this when the file was deleted, got damaged (one bad edit is enough), or came from another server carrying details that mean nothing here.
What the file has to contain
| Line |
What it is |
| DB_NAME |
The database name, with the account prefix in front. |
| DB_USER |
The MySQL user, also prefixed. |
| DB_PASSWORD |
That user’s password. If you do not know it, set a new one in cPanel and use that. |
| DB_HOST |
Here it is localhost. |
| $table_prefix |
This is the one most people get wrong. It has to be exactly the prefix of the tables sitting in the database. If the tables are called xyz_posts, the prefix is xyz_ and not wp_. |
| The security keys |
Eight long lines of random text that encrypt the session cookies. They do not have to be the old ones. |
Step by step
| 1 |
Keep what is there. If a wp-config.php still exists, download it to your computer before touching anything. Do not rename it to .bak or .txt inside public_html: files like that are served as plain text and the password goes public.
|
|
| 2 |
Confirm the prefix. Open phpMyAdmin, go into the site’s database and look at the table names. Whatever comes before posts and options is the prefix.
|
|
| 3 |
Start from the template. There is a wp-config-sample.php in the site folder. Copy it (right click, Copy) to wp-config.php and edit the copy. Never edit the template.
|
|
| 4 |
Fill in the five lines from the table above, with single quotes and a semicolon at the end of each, exactly as the template has them.
|
|
| 5 |
Replace the security keys. In the template they are a block with put your unique phrase here repeated. Replace each one with a long, different phrase. If you would rather not invent them: password generator.
|
|
| 6 |
Save and open the site. If it opens, you are done.
|
|
|
Changing the keys signs everybody out. You included. Open sessions drop and you have to sign in again. It is not a defect, and it is in fact the fastest way to eject anyone who should not be there. But know it is coming.
|
The symptoms, and what each one means
| After saving you see |
What is wrong |
| The WordPress installation screen |
The connection works, but WordPress cannot find its tables. Nearly always the wrong $table_prefix. Second possibility: you connected to the wrong database, which is empty. |
| «Error establishing a database connection» |
Name, user, password or the link between them: the causes, in order. |
| A blank page |
A syntax error in the file: a missing quote, a forgotten semicolon, or spaces after the closing ?>. See common WordPress errors. |
| The site opens but images and menus do not |
The database is right and the address stored in it is not. That is fixed in wp_options: cannot get into the dashboard. |
Two lines worth adding
Since the file is open anyway, there are two lines that save work later. They go above the line saying That’s all, stop editing:
| Line |
What for |
| define( 'WP_HOME', 'https://yourcompany.com' ); and define( 'WP_SITEURL', 'https://yourcompany.com' ); |
They force the site address, overriding whatever is in the database. It is the remedy for redirect loops after changing domain. |
| define( 'DISALLOW_FILE_EDIT', true ); |
Switches off the theme and plugin editor in the dashboard, which is the first tool anyone who gets in uninvited reaches for. |
|
Set the permissions at the end. In File Manager, right click wp-config.php, Permissions, and set 600. It is the file with the database password: only the account needs to read it. If the site stops opening at 600, use 640.
|
If the file will not work again
A wp-config.php from a day the site worked is in the backups, and it comes back on its own without restoring the whole site: how to restore your data. It is the short route once you have tried twice.
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from R180.00/mo See plans |