wp-config.php Basic Settings: From File Location to Memory and Revisions

Affiliate disclosure v3.1
Affiliate disclosure v3.2 (mobile)

The wp-config.php file is the most important configuration file: on a WordPress website it holds the core information, everything WordPress needs to connect to its database and run, so it works as the heart of the site.

Ⅰ. What wp-config.php Does

This file contains the following sensitive settings.

  • Database connection details
  • ↳ It holds the details required to connect to the database that stores WordPress content, such as the MySQL or MariaDB database name, username, password and host.
  • Security keys and salts
  • ↳ Unique random strings used to encrypt users' login sessions and cookies. Without these keys, sessions cannot be kept secure.
  • Other core settings
  • ↳ It defines important constants that control how WordPress works, such as the table prefix, turning debug mode on or off, and disabling file editing.
WordPress wp-config.php file

Because of this, the wp-config.php file is the top target, the first thing outside attackers go after. If its permissions are set wrong or its contents are exposed, the whole database can leak or attackers can take over admin rights, which makes it a serious security vulnerability. The first step in hardening WordPress security is therefore keeping this file safe.

1️⃣ Where wp-config.php Is Located

wp-config.php sits in the top-level folder where WordPress is installed, next to the [wp-admin], [wp-content] and [wp-includes] folders. On cPanel hosting that folder is [public_html]; this site keeps it at [/home/uknew/www/wp-config.php] on a Lightsail VPS.

If you cannot see the file in the top-level folder, check the folder one level up. WordPress looks for wp-config.php in the installation folder first and, if it is not there, loads it from the folder directly above.

2️⃣ How to Open wp-config.php

In your hosting control panel's [File Manager], go to the top-level folder, right-click wp-config.php and choose [Edit]. This lets you edit it right in the browser without any other program.

An FTP client (FileZilla): download the file to your computer, edit it in an editor and upload it again. Keep a separate copy of the original before uploading so you can restore it right away if something breaks.

On servers such as a VPS that you reach over SSH, run an editor followed by the file path, as with [vi]; [nano] opens it the same way.

vi /home/uknew/www/wp-config.php

3️⃣ wp-config-sample.php and the Basic Structure

A freshly downloaded WordPress package has no wp-config.php, only [wp-config-sample.php] in the same place. When you enter your database details on the install screen, WordPress creates wp-config.php from this file; copying and renaming it yourself gives the same result.

define( 'DB_NAME', 'database_name_here' );
define( 'DB_USER', 'username_here' );
define( 'DB_PASSWORD', 'password_here' );
define( 'DB_HOST', 'localhost' );
define( 'DB_CHARSET', 'utf8mb4' );
define( 'DB_COLLATE', '' );

define( 'AUTH_KEY',         'put your unique phrase here' );
define( 'SECURE_AUTH_KEY',  'put your unique phrase here' );
define( 'LOGGED_IN_KEY',    'put your unique phrase here' );
define( 'NONCE_KEY',        'put your unique phrase here' );
define( 'AUTH_SALT',        'put your unique phrase here' );
define( 'SECURE_AUTH_SALT', 'put your unique phrase here' );
define( 'LOGGED_IN_SALT',   'put your unique phrase here' );
define( 'NONCE_SALT',       'put your unique phrase here' );

$table_prefix = 'wp_';

define( 'WP_DEBUG', false );

The four lines [DB_NAME], [DB_USER], [DB_PASSWORD] and [DB_HOST] take the database details from your host. If even one value is wrong, visitors see the [Error establishing a database connection] message instead of the site.

The eight lines from [AUTH_KEY] to [NONCE_SALT] encrypt login cookies; get a fresh set from [https://api.wordpress.org/secret-key/1.1/salt/] and replace them all at once. Changing them logs out every signed-in user.

[$table_prefix] is the prefix added to database table names, [wp_] by default, and it keeps several WordPress installs apart when they share one database. Setting [WP_DEBUG] to [true] shows PHP errors, which appear on screen, so keep it at [false] on a live site.

Ⅱ. /* That’s all, stop editing! Happy publishing. */

Technically, this comment (/* That’s all, stop editing! Happy publishing. */) does nothing special as PHP code. It is just a comment.

But the WordPress team left it as a ‘marker‘ : a note telling users, “the core code WordPress needs to run is below this comment, so do not touch it.”

1️⃣ Key Point: Why Code Goes above this comment

The WordPress wp-config.php file ends with the following structure.

// (omitted: Database info, Security keys, Table prefix etc.)

/**
 * For developers: WordPress debugging mode.
 *
 * Change this to true to enable the display of notices during development.
 * It is strongly recommended that plugin and theme developers use WP_DEBUG
 * in their development environments.
 */
define( 'WP_DEBUG', false );
### 
/* That's all, stop editing! Happy publishing. */

/** Absolute path to the WordPress directory. */
if ( ! defined( 'ABSPATH' ) ) {
	define( 'ABSPATH', dirname( __FILE__ ) . '/' );
}

/** Sets up WordPress vars and included files. */
require_once( ABSPATH . 'wp-settings.php' );
  1. Setting constants (define) go above: Most WordPress setting constants (define) must be defined /* That’s all, stop editing! Happy publishing. */ directly above the comment so that WordPress loads them correctly while it initializes its settings.
  2. WordPress loading starts below: Below this comment are the [ABSPATH] definition and the code [require_once( ABSPATH . ‘wp-settings.php’ );]. From the moment this [wp-settings.php] file loads, WordPress's core features actually start running.

So when you add extra settings (for example, disabling file editing with [define(‘DISALLOW_FILE_EDIT’, true);] or setting a memory limit with [define(‘WP_MEMORY_LIMIT’, ‘256M’);]), write them so they load first, ahead of WordPress's core loading file, that is, directly above the comment, so they apply without errors.

wp-config-sample.php has one more comment, [Add any custom values between this line and the “stop editing” line.], right above the [stop editing] comment; put your own settings between these two comments.

Ⅲ. Basic wp-config.php Settings to Apply After Installing WordPress

1️⃣ Heartbeat Settings

The WordPress ‘Heartbeat’ is a signal that checks whether the server and the website are still connected. The Heartbeat API uses 
/wp-admin/admin-ajax.php, through which it makes AJAX calls from the browser. In the WordPress dashboard, this file sends a POST request every 15 seconds.

You can keep it running only on the post editor screens, [post.php]·[post-new.php].

Heartbeat has no wp-config.php constant, so this file cannot control it. If you put the code below in wp-config.php, it runs before WordPress loads the [add_action] function, and the site stops with a [Call to undefined function add_action()] error.

WP Rocket: on the [Heartbeat] tab, choose [Do not limit], [Reduce activity] or [Disable] for the backend, the post editor and the frontend.

WP Rocket Heartbeat settings screen

Perfmatters: [Disable Heartbeat] sets the screens where Heartbeat is allowed, and [Heartbeat Frequency] sets the request interval.

Perfmatters Heartbeat settings

If you use neither plugin, do not install another plugin just for Heartbeat. Plugins leave their settings in the database even after you delete them, so put the code below in your theme's [functions.php] instead.

/** Disable Heartbeat everywhere except post editor */
add_action('init', function() {
    global $pagenow;
    if ($pagenow != 'post.php' && $pagenow != 'post-new.php') {
        wp_deregister_script('heartbeat');
    }
}, 1);

2️⃣ WordPress Memory Settings

The memory setting caps how much memory WordPress can use in PHP, to prevent out-of-memory errors (Fatal error: Allowed memory size exhausted) while themes or plugins run. In other words, for a stable site that stays within its resources, it is a basic safeguard.

Most WordPress tutorials and the official docs show only [define(‘WP_MEMORY_LIMIT’, ‘256M’);].

/** Memory Limit for WordPress */
define('WP_MEMORY_LIMIT', '256M');      // frontend
define('WP_MAX_MEMORY_LIMIT', '512M');  // admin/backend

‘WP_MAX_MEMORY_LIMIT’ is a setting that allows more memory in the backend than in the frontend.

WP_MEMORY_LIMIT is the “memory limit for site visitors”,
and WP_MAX_MEMORY_LIMIT is the “extended limit for admin and internal tasks”.
You need to set both to get full control of WordPress memory.

If the value in wp-config.php is higher than the server's php.ini or PHP-FPM pool setting, the server setting wins.

3️⃣ Limiting Revisions

WordPress revisions keep piling up earlier versions of every post, which slows the site down. On sites without caching, and even on cached sites while you work in the dashboard, especially when writing posts or pages, the visitor-facing pages can slow down too.

For example, when the server is using about 50% of its total CPU, visitor pages can slow down no matter which cache plugin you use.

That is why you turn revisions off or limit how many are kept.

You do not need a separate plugin to set the number of revisions. One constant line in wp-config.php does the same job, and it leaves no plugin settings behind in the database to clean up later.

◽️️Turn off revisions completely

/** Disable Post Revisions completely */
define('WP_POST_REVISIONS', false);

◽️️Limit revisions to a set number (e.g. 3)

/** Limit Post Revisions to 3 per post */
define('WP_POST_REVISIONS', 3);

◽️️Adjust the autosave interval

WordPress autosaves posts every minute by default. You can raise it, for example, from the default 60 seconds to 5 minutes (300 seconds).

/** Increase autosave interval to 5 minutes */
define('AUTOSAVE_INTERVAL', 300);

If you use WP Rocket or Perfmatters, you can also handle this in their settings screens. WP Rocket: its [Revisions] option on the [Database] tab deletes revisions that have already piled up, and it has no setting to limit how many are kept.

WP Rocket database revision cleanup screen

Perfmatters: [Limit Post Revisions] sets how many revisions to keep per post, and [Autosave Interval] sets the autosave interval.

Perfmatters revision limit settings

🔢 FAQ & Recommended Content

If the line you just saved is missing a quote or a semicolon, PHP cannot read wp-config.php to the end and the site will not open. Restore the original you saved before editing, then check only the lines you changed.

Our wp-config.php security article: it recommends [600], which lets only the owner read and write the file. On servers where PHP runs under a different account from the file owner, PHP cannot read the file at 600, so check that the site still opens right after changing it.

When you activate WP Rocket, it adds the line [define( ‘WP_CACHE’, true ); // Added by WP Rocket] at the top of the file; this site's wp-config.php has it on line 2. WordPress only loads the cache file [advanced-cache.php] when this line is present.

If the same constant is already defined higher up in the file, PHP keeps the first value and only logs a [Constant WP_MEMORY_LIMIT already defined] warning for the later line. Search the whole file for the constant name to find lines added by your host or a plugin.

ℹ️ Affiliate Disclosure
This site's content contains affiliate links. When a visitor buys a product or service through one of them, the site receives a commission from the seller. The amount the buyer pays(it goes down during event discounts ↓)does not go up. Posted prices, discounts, and stock reflect the time of writing and may differ, so confirm with the seller before buying. Products are chosen and reviewed by our own standards, and commissions do not affect the order or content of reviews.

Leave a Reply

Your email address will not be published. Required fields are marked *

Prove your humanity: 9   +   2   =