[wp-trac] [WordPress Trac] #18546: Add index.php to wp-includes and wp-admin/includes

WordPress Trac wp-trac at lists.automattic.com
Wed Sep 5 17:38:18 UTC 2012


#18546: Add index.php to wp-includes and wp-admin/includes
------------------------------------+------------------------------
 Reporter:  SergeyBiryukov          |       Owner:
     Type:  enhancement             |      Status:  reopened
 Priority:  low                     |   Milestone:  Awaiting Review
Component:  General                 |     Version:  3.2
 Severity:  minor                   |  Resolution:
 Keywords:  dev-feedback has-patch  |
------------------------------------+------------------------------
Changes (by SergeyBiryukov):

 * component:  Security => General


Comment:

 Replying to [comment:6 bpetty]:
 > Silencing wp-includes or wp-admin is really completely pointless, and
 doesn't help secure anything or hide any sensitive content.

 This isn't for security, the idea was to prevent unnecessary crawling and
 irrelevant errors in server logs.

 For the most part, this is fixed in #18465, but not for installations in
 subdirectories or without `.htaccess`, in which case `do_robots()` doesn't
 get called.

 Another way to address this might be trying to create an `.htaccess` file
 on install (which was previously suggested for #6481) if it doesn't exist
 yet and the permissions allow to do that. This would have an additional
 bonus of displaying 404 pages in theme layout even with default
 permalinks.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/18546#comment:9>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list