Ideally, config.php shouldn’t be writeable by theme or plugin files to ensure WordPress security standards. However, there are certain cases when you might want to make changes to wp-config constants. Making wp-config writeable or changeable by other themes/plugin files is not recommended. Think of a case when you did hard work and ran your WordPress […]
config.php shouldn’t be writeable by theme or plugin files to ensure WordPress security standards. However, there are certain cases when you might want to make changes to wp-config constants.
Think of a case when you did hard work and ran your WordPress site successfully and it got errors due to another theme/plugin trying to modify the wp-config contents. Not good, right?
You can easily, very quickly, get hacked if you allow changes to the wp-config theme/plugin file. In other words, you will open the door for everyone to come into your website code files and make changes as they want. I think you clearly don’t want it.
By default, considering the security, Worpdress hasn’t introduced any mechanism to make changes or override the contents of
wp-config file contents with an exception of some setting constants.
If you want to change database constant values which reside in wp-config, you cannot do it from other files. This makes sense.
If you want to update the file upload size or maximum time for script execution, you can change it directly within wp-config and not from other files. This also makes sense.
On the other hand, if you want to disable post revisions for a specific post type or enable the use of the WordPress media uploads features, you can do it via theme’s functions.php or plugin file.
You can also create rest routes, custom endpoints, rewrite rules, add new database tables, or more via theme/plugin files.
Consider a case where a developer is trying to build a ready-to-use and complete solution for non-tech and low-budget business owners. Instead of guiding or just adding written recommendations or teaching the technical solutions to non-tech people, a plugin author might want to do the following:
There could be many other rationales for modifying wp-config by a theme/plugin author.
Firstly understand that changing WordPress core constants from the theme/plugin directory is not recommended. Moreover, providing an option (even to non-tech owners or newbie developers) to update modifiable wp-config constants is not recommended.
Secondly, know the type of constant you are trying to update. Analyze the use of that constant to figure out if we can change it from functions.php or plugin file or not. If it’s not a database or core related, such as auto-saving timing, here is how to do it.
These steps are meant for a good cause and informational purposes only. We highly recommend consulting and hiring a website maintenance or support team to let them make changes after the feasibility and requirement analysis of your particular case.
define( 'WP_DEBUG_DISPLAY', false)in
wp-config(recommended) or in functions.php.
WordPress has a default loading hierarchy and priority setting. Starting from
index.php loading the WordPress core header to reaching the theme and plugins at the end, you might not see the quick effect of overridden values for a while.
As soon as the WP reaches your part of the code, it’ll update the default or previous value. Therefore, you might see the effect of your changes late and this makes sense.
Since overriding wp-config constants from other files are not right, neither recommended, nor obvious mechanism is available, therefore, tolerating this delay in value change shouldn’t be frustrating.
Digital Setups has enforced a strict sourcing policy. Every content piece published on our website is passed through strict editorial review for contextual correctness, communication ethics, and programmatic tests wherever required. Our team research solutions from only credible, authentic, and trustworthy sources. Learn more about our editorial process.
Our standardized editorial process ensures right, timely, and healthy updates to our content. Your honest opinion drives significant improvement to our content. We appreciate you are taking time to share that.