.htaccess for PHP projects: friendly URLs and redirects

The .htaccess file is where you tell the server how to treat addresses: send every request to a single index.php file (friendly URLs), redirect one address to another, and hide what must not be public. It is plain text, sits in the site folder, and the server reads it on every request.

What each need calls for

I want… Directive Note
Friendly URLs (a single entry point) RewriteRule to index.php It is what most PHP applications expect. First block below.
To move a page Redirect 301 The 301 tells search engines the move is permanent.
One address for the site (with or without www) RewriteCond and RewriteRule Stops the same site living at two addresses.
To force https RewriteCond and RewriteRule Already described in redirecting HTTP to HTTPS.
To hide files such as .env FilesMatch Last block below.

The blocks used most

Friendly URLs: anything that is not an existing file or folder goes to index.php.

RewriteEngine On
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule ^ index.php [L]

A page that moved:

Redirect 301 /old-page.html /new-page.html

No www only (swap in your own name, keeping the dots written as shown):

RewriteEngine On
RewriteCond %{HTTP_HOST} ^www\.yourdomain\.tld$ [NC]
RewriteRule ^(.*)$ https://yourdomain.tld/$1 [R=301,L]

Hide files that start with a dot (such as .env or .git):

<FilesMatch "^\.">
Require all denied
</FilesMatch>

Before you touch it

1 Copy the .htaccess before editing it: click it and choose copy in the File Manager.
2 Change one thing at a time and open the site after every change. A typing error in a single character gives a 500 error on the whole site.
3 Test with 302 and switch to 301 at the end. The browser remembers a 301 for a long time; if you get the destination wrong, it keeps going to the wrong place even after you fix it. Test in a private window.
4 Order matters: redirects go before the index.php block.

Two closing notes. A .htaccess applies to the folder it sits in and the folders inside it, and the rules of an inner folder run in addition to the ones above. And write a comment (a line starting with #) explaining each block you add: a year from now, nobody remembers why it is there.

WordPress writes its own block, between the lines “BEGIN WordPress” and “END WordPress”. Do not edit inside it: WordPress rewrites it. Put your rules above or below. If WordPress addresses return 404, see permalinks and the 404 that follows.
Got a 500 after saving? Go back to the copy. The error nearly always comes from the last line you added. See also error 403: permissions, .htaccess and blocked IPs and, to redirect without losing your Google positions, 301 redirects.

Saved the .htaccess and the site gave a 500 error? Tell us the time and what you added.

Open a support ticket

SEE ALSO

How to redirect HTTP to HTTPS with .htaccess

301 redirects when you change a page or a domain

Error 403 Forbidden: permissions, .htaccess and blocked IPs

WordPress permalinks and the 404 that follows

RECOMMENDED PRODUCT

Web hosting with cPanel

Domain and SSL included, daily backups and the panel you already know. from $6.60/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?