[wp-trac] [WordPress Trac] #18546: Add index.php to wp-includes and wp-admin/includes

WordPress Trac noreply at wordpress.org
Mon May 4 15:19:53 UTC 2020


#18546: Add index.php to wp-includes and wp-admin/includes
-------------------------------------------------+-------------------------
 Reporter:  SergeyBiryukov                       |       Owner:  (none)
     Type:  enhancement                          |      Status:  reopened
 Priority:  normal                               |   Milestone:  Awaiting
                                                 |  Review
Component:  Bootstrap/Load                       |     Version:  3.2
 Severity:  normal                               |  Resolution:
 Keywords:  dev-feedback has-patch needs-        |     Focuses:
  refresh                                        |
-------------------------------------------------+-------------------------

Comment (by jonoaldersonwp):

 Given that there's been some recent conversation about this
 (https://core.trac.wordpress.org/ticket/50076), and as this ticket seems
 to be a bit stale, it's worth revisiting that:

 - We can't reliably rely on server/hosting setups to manage this well.
 - It's a persistent SEO and (arguably, though secondarily) security risk.
 - Adding index files to all folders is the only viable/reliable/universal
 solution to this.
 - (and in an ideal world, we'd also have those index files trigger the
 themes' 404 template and return a 404 HTTP status).
 - Yes, it's a challenge to enforce this across
 customisations/plugins/themes, but, some progress is better than none.

 TL;DR, "yes, we need to add index files to all folders".

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/18546#comment:18>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list