wp-config.php Basic Settings: From File Location to Memory and Revisions

The wp-config.php file is the most important configuration file: on a WordPress website it holds the core information, everything WordPress needs to connect to its database and run, so it works as the heart of the site.
Ⅰ. What wp-config.php Does
This file contains the following sensitive settings.

Because of this, the wp-config.php file is the top target, the first thing outside attackers go after. If its permissions are set wrong or its contents are exposed, the whole database can leak or attackers can take over admin rights, which makes it a serious security vulnerability. The first step in hardening WordPress security is therefore keeping this file safe.
1️⃣ Where wp-config.php Is Located
wp-config.php sits in the top-level folder where WordPress is installed, next to the [wp-admin], [wp-content] and [wp-includes] folders. On cPanel hosting that folder is [public_html]; this site keeps it at [/home/uknew/www/wp-config.php] on a Lightsail VPS.
If you cannot see the file in the top-level folder, check the folder one level up. WordPress looks for wp-config.php in the installation folder first and, if it is not there, loads it from the folder directly above.
2️⃣ How to Open wp-config.php
In your hosting control panel's [File Manager], go to the top-level folder, right-click wp-config.php and choose [Edit]. This lets you edit it right in the browser without any other program.
An FTP client (FileZilla): download the file to your computer, edit it in an editor and upload it again. Keep a separate copy of the original before uploading so you can restore it right away if something breaks.
On servers such as a VPS that you reach over SSH, run an editor followed by the file path, as with [vi]; [nano] opens it the same way.
vi /home/uknew/www/wp-config.php3️⃣ wp-config-sample.php and the Basic Structure
A freshly downloaded WordPress package has no wp-config.php, only [wp-config-sample.php] in the same place. When you enter your database details on the install screen, WordPress creates wp-config.php from this file; copying and renaming it yourself gives the same result.
define( 'DB_NAME', 'database_name_here' );
define( 'DB_USER', 'username_here' );
define( 'DB_PASSWORD', 'password_here' );
define( 'DB_HOST', 'localhost' );
define( 'DB_CHARSET', 'utf8mb4' );
define( 'DB_COLLATE', '' );
define( 'AUTH_KEY', 'put your unique phrase here' );
define( 'SECURE_AUTH_KEY', 'put your unique phrase here' );
define( 'LOGGED_IN_KEY', 'put your unique phrase here' );
define( 'NONCE_KEY', 'put your unique phrase here' );
define( 'AUTH_SALT', 'put your unique phrase here' );
define( 'SECURE_AUTH_SALT', 'put your unique phrase here' );
define( 'LOGGED_IN_SALT', 'put your unique phrase here' );
define( 'NONCE_SALT', 'put your unique phrase here' );
$table_prefix = 'wp_';
define( 'WP_DEBUG', false );The four lines [DB_NAME], [DB_USER], [DB_PASSWORD] and [DB_HOST] take the database details from your host. If even one value is wrong, visitors see the [Error establishing a database connection] message instead of the site.
The eight lines from [AUTH_KEY] to [NONCE_SALT] encrypt login cookies; get a fresh set from [https://api.wordpress.org/secret-key/1.1/salt/] and replace them all at once. Changing them logs out every signed-in user.
[$table_prefix] is the prefix added to database table names, [wp_] by default, and it keeps several WordPress installs apart when they share one database. Setting [WP_DEBUG] to [true] shows PHP errors, which appear on screen, so keep it at [false] on a live site.
Ⅱ. /* That’s all, stop editing! Happy publishing. */
Technically, this comment (/* That’s all, stop editing! Happy publishing. */) does nothing special as PHP code. It is just a comment.
But the WordPress team left it as a ‘marker‘ : a note telling users, “the core code WordPress needs to run is below this comment, so do not touch it.”
1️⃣ Key Point: Why Code Goes above this comment
The WordPress wp-config.php file ends with the following structure.
// (omitted: Database info, Security keys, Table prefix etc.)
/**
* For developers: WordPress debugging mode.
*
* Change this to true to enable the display of notices during development.
* It is strongly recommended that plugin and theme developers use WP_DEBUG
* in their development environments.
*/
define( 'WP_DEBUG', false );
###
/* That's all, stop editing! Happy publishing. */
/** Absolute path to the WordPress directory. */
if ( ! defined( 'ABSPATH' ) ) {
define( 'ABSPATH', dirname( __FILE__ ) . '/' );
}
/** Sets up WordPress vars and included files. */
require_once( ABSPATH . 'wp-settings.php' );- Setting constants (define) go above: Most WordPress setting constants (define) must be defined /* That’s all, stop editing! Happy publishing. */ directly above the comment so that WordPress loads them correctly while it initializes its settings.
- WordPress loading starts below: Below this comment are the [ABSPATH] definition and the code [require_once( ABSPATH . ‘wp-settings.php’ );]. From the moment this [wp-settings.php] file loads, WordPress's core features actually start running.
So when you add extra settings (for example, disabling file editing with [define(‘DISALLOW_FILE_EDIT’, true);] or setting a memory limit with [define(‘WP_MEMORY_LIMIT’, ‘256M’);]), write them so they load first, ahead of WordPress's core loading file, that is, directly above the comment, so they apply without errors.
wp-config-sample.php has one more comment, [Add any custom values between this line and the “stop editing” line.], right above the [stop editing] comment; put your own settings between these two comments.
Ⅲ. Basic wp-config.php Settings to Apply After Installing WordPress
1️⃣ Heartbeat Settings
The WordPress ‘Heartbeat’ is a signal that checks whether the server and the website are still connected. The Heartbeat API uses
/wp-admin/admin-ajax.php, through which it makes AJAX calls from the browser. In the WordPress dashboard, this file sends a POST request every 15 seconds.
You can keep it running only on the post editor screens, [post.php]·[post-new.php].
Heartbeat has no wp-config.php constant, so this file cannot control it. If you put the code below in wp-config.php, it runs before WordPress loads the [add_action] function, and the site stops with a [Call to undefined function add_action()] error.
WP Rocket: on the [Heartbeat] tab, choose [Do not limit], [Reduce activity] or [Disable] for the backend, the post editor and the frontend.

Perfmatters: [Disable Heartbeat] sets the screens where Heartbeat is allowed, and [Heartbeat Frequency] sets the request interval.

If you use neither plugin, do not install another plugin just for Heartbeat. Plugins leave their settings in the database even after you delete them, so put the code below in your theme's [functions.php] instead.
/** Disable Heartbeat everywhere except post editor */
add_action('init', function() {
global $pagenow;
if ($pagenow != 'post.php' && $pagenow != 'post-new.php') {
wp_deregister_script('heartbeat');
}
}, 1);2️⃣ WordPress Memory Settings
The memory setting caps how much memory WordPress can use in PHP, to prevent out-of-memory errors (Fatal error: Allowed memory size exhausted) while themes or plugins run. In other words, for a stable site that stays within its resources, it is a basic safeguard.
Most WordPress tutorials and the official docs show only [define(‘WP_MEMORY_LIMIT’, ‘256M’);].
/** Memory Limit for WordPress */
define('WP_MEMORY_LIMIT', '256M'); // frontend
define('WP_MAX_MEMORY_LIMIT', '512M'); // admin/backend‘WP_MAX_MEMORY_LIMIT’ is a setting that allows more memory in the backend than in the frontend.
WP_MEMORY_LIMIT is the “memory limit for site visitors”,
and WP_MAX_MEMORY_LIMIT is the “extended limit for admin and internal tasks”.
You need to set both to get full control of WordPress memory.If the value in wp-config.php is higher than the server's php.ini or PHP-FPM pool setting, the server setting wins.
3️⃣ Limiting Revisions
WordPress revisions keep piling up earlier versions of every post, which slows the site down. On sites without caching, and even on cached sites while you work in the dashboard, especially when writing posts or pages, the visitor-facing pages can slow down too.
For example, when the server is using about 50% of its total CPU, visitor pages can slow down no matter which cache plugin you use.
That is why you turn revisions off or limit how many are kept.
You do not need a separate plugin to set the number of revisions. One constant line in wp-config.php does the same job, and it leaves no plugin settings behind in the database to clean up later.
◽️️Turn off revisions completely
/** Disable Post Revisions completely */
define('WP_POST_REVISIONS', false);◽️️Limit revisions to a set number (e.g. 3)
/** Limit Post Revisions to 3 per post */
define('WP_POST_REVISIONS', 3);◽️️Adjust the autosave interval
WordPress autosaves posts every minute by default. You can raise it, for example, from the default 60 seconds to 5 minutes (300 seconds).
/** Increase autosave interval to 5 minutes */
define('AUTOSAVE_INTERVAL', 300);If you use WP Rocket or Perfmatters, you can also handle this in their settings screens. WP Rocket: its [Revisions] option on the [Database] tab deletes revisions that have already piled up, and it has no setting to limit how many are kept.

Perfmatters: [Limit Post Revisions] sets how many revisions to keep per post, and [Autosave Interval] sets the autosave interval.

🔢 FAQ & Recommended Content
Performance
Disabling WP-Cron and Using System Cron
How to turn off wp-cron.php, which runs on every page load, and move it to a server cron job.
Settings
2 Ways to Stop the FTP Credentials Prompt
Two ways to remove the FTP login box that appears every time you update a plugin.
Error
Critical Error: Causes and Fix
How the cause was found and fixed when the [There has been a critical error] message appeared.
ℹ️ Affiliate Disclosure
This site's content contains affiliate links. When a visitor buys a product or service through one of them, the site receives a commission from the seller. The amount the buyer pays(it goes down during event discounts ↓)does not go up. Posted prices, discounts, and stock reflect the time of writing and may differ, so confirm with the seller before buying. Products are chosen and reviewed by our own standards, and commissions do not affect the order or content of reviews.