To make sure only people with a username and password can open a folder of the site (a private area, a test site, a folder of files for a customer), use cPanel’s Directory Privacy. Whoever opens the address sees a browser box asking for credentials before seeing anything. It takes five minutes and needs no code.
Step by step
| 1 |
In cPanel, in the Files section, open Directory Privacy. If you have several domains, pick the domain whose folder you want to protect.
|
|
| 2 |
Browse to the folder and click its name to select it. Clicking the icon only opens the folder; it is the name that picks it.
|
|
| 3 |
Tick Password protect this directory. and, in the next field, type the name that appears on the sign-in box (for example “Private area”). Click Save.
|
|
| 4 |
In the users section, fill in the user name, the password and its confirmation, and click Create User. Use the password generator: password generator.
|
|
| 5 |
Test in a private window. Open the folder’s address: the credentials box should appear. If the browser opens the folder without asking, it stayed in memory from an earlier visit.
|
|
What happens underneath
cPanel adds authentication rules to that folder’s .htaccess file and keeps the encrypted password in a file of the account, outside the public folder. The protection covers the folder and everything inside it, subfolders included. To remove it, go back to the same screen and untick the option.
| Works well for |
Does not work for |
| A test site you do not want visible (see a test site before touching what is live) |
Holding sensitive data: it is a door with a simple key, not a vault |
| A folder of files for a customer |
Folders that outside programs must reach with no person: they cannot answer the box |
| Temporarily hiding a site under construction |
Stopping copies by someone who already has the password |
|
It can break things that rely on automatic requests. Webhooks, links from other services and WordPress tasks that call addresses inside the folder end up knocking on a door with no answer. If you protected a folder and something stopped working, that is the first suspect. For the specific case of wp-admin, the warning and the fix are in protecting the WordPress login.
|
|
Do not hand-edit the .htaccess cPanel has just written without keeping a copy. One slip and the folder is open, or the server returns error 500. When you only want to block one address, the road is another: blocking an IP address.
|
|
The credentials box does not appear, or appears where it should not? Tell us the folder’s address.
Open a support ticket
|
RECOMMENDED PRODUCT Web hosting with cPanel Domain and SSL included, daily backups and the panel you already know. from $6.59/mo (3-year plan, with coupon) See plans |