Disable file editing in WordPress with or without DISALLOW_FILE_EDIT
WordPress ships with two code editors in the dashboard, one for themes and one for plugins. Anyone with an administrator account can open them and change PHP that runs on every page, straight from the browser. Most sites never need that, which is why it is worth knowing how to disable file editing in WordPress.
The usual way is a line in wp-config.php. BetterShield offers the same result as a switch, with nothing to edit and an undo. This guide covers why, both ways of doing it, what it can affect, and how to put the editors back.
Quick summary
- The audit reports The dashboard file editor is enabled as Medium, costing 7 points while open.
DISALLOW_FILE_EDITin wp-config.php removes the editors. BetterShield’s Disable the dashboard file editor removes them too, without touching wp-config.php.- What it can affect, in the plugin’s own words: “Could break: nothing. Files stay editable over SFTP and through your host.”
- Installing, updating and activating plugins and themes carry on as before.
- To put the editors back, turn the switch off. If wp-config.php also sets the constant, remove that line too.
Why disable file editing in WordPress
The theme and plugin file editors save straight to the live files. There is no review step and no copy of what was there before, so a change goes live the moment it is saved.
That is a lot of reach for one browser session. BetterShield’s audit puts it this way: the editor “lets anyone with admin access edit code from the browser.” If someone else ever gets hold of an administrator’s session, the editor is the shortest path from that session to changing your code.
Turning it off takes that path away, and costs most sites nothing. Theme and plugin code can still be changed through SFTP, your host’s file manager or a deployment, where a change is a deliberate step.
The audit finding for the file editor
On BetterShield › Findings, The dashboard file editor is enabled sits in the Exposure area at Medium severity and takes 7 points off your score while open. Explain shows why it matters and what could break, and Apply fix turns on the fix straight away.
It is also one of the findings Worth doing first on the Overview can list, and one of the five safe fixes Quick Setup offers, as Turn off the file editor. See Score and findings and the checklist.
Option 1: DISALLOW_FILE_EDIT in wp-config.php
WordPress has a constant for this. Add this line to wp-config.php, above the line that says to stop editing:
define( 'DISALLOW_FILE_EDIT', true );
WordPress then refuses the capabilities behind the editors for every account, and the editor screens disappear.
This works well, and it is the right choice if you manage wp-config.php in version control or across many sites. It needs file access to set and to undo, and a mistake in wp-config.php can stop the site loading, so edit it carefully.
BetterShield reads the constant. If wp-config.php already sets it, the audit treats the editor as off, and the fix’s row says: “wp-config.php already disables the file editor, so applying this changes nothing today. It stays useful if that line is ever removed.”
Option 2: BetterShield’s one-click fix
The fix does the same job as the constant while WordPress runs. It refuses the three editing capabilities for every role, administrators included, and writes no file.
- Open BetterShield › Protect › Hardening. Disable the dashboard file editor is under What can run: “Removes the built-in plugin and theme code editors from the dashboard.”
- Press Preview the change. It lists what applying would do and changes nothing.
- Turn the switch on. The row shows On since and Undo never expires, and “Hardening applied” is written to the activity log.
The editors leave the dashboard at once, and the finding moves to Fixed. If it is still listed, press Run audit.
There is no page a visitor sees that could prove this one, so the row says it is reported from your settings. From the terminal, wp bettershield harden file_editor --user=<login> applies it (WP-CLI commands).
A connected AI assistant allowed to make changes can also apply this fix directly. It is one of seven fixes an assistant may turn on by itself, each with a way back. See Connect an AI assistant.
What disabling file editing can affect
For most sites, nothing visible. Specifically:
- The editors are gone for everyone. Administrators lose them too. That is the point, but tell anyone who used them.
- Code changes move elsewhere. Use SFTP, your host’s file manager or your deployment process.
- Plugins and themes still install and update. Only the three editing capabilities are refused. Installing, updating, activating and deleting are left alone.
- Safe mode brings the editors back for a while. Safe mode, started from your recovery link, pauses every fix, this one included, until it ends.
- On a multisite network, it changes nothing for a site administrator. The editors already belong to the network’s own administrators, and the row says so. See Multisite networks.
If a theme or plugin file is changed by any route, BetterShield’s file check can still show it: WordPress core and directory plugins are compared with the official copies, and your theme is watched for changes. See WordPress file integrity check.
How to put the file editor back
- On Protect › Hardening, turn Disable the dashboard file editor off. The editors return at once.
- If Ask for my password before an action that removes a protection is on under Settings › General, enter your password when asked.
- If wp-config.php also sets
DISALLOW_FILE_EDIT, remove that line or set it tofalse. BetterShield’s undo cannot reach a constant it never wrote.
From the terminal, wp bettershield harden file_editor --undo --user=<login> does the same. Undoing a fix needs a signed-in browser session or the command line; it is refused over an application password. An AI assistant can only take it off through a plan you agree to in the conversation.
Once the editors are back, the audit runs again and the finding returns to the report. If you need the editor for an afternoon, turn the fix off, make your change, and turn it back on. “Hardening undone” and “Hardening applied” both appear in the log; see Activity log.
Common mistakes
- Setting both and expecting the switch to undo both. The switch only reverses its own change. A
DISALLOW_FILE_EDITline keeps the editors off until you remove it. - Confusing it with DISALLOW_FILE_MODS. That constant goes further and also stops installs and updates from the dashboard. BetterShield’s fix does not.
- Editing wp-config.php in a hurry. If you take the constant route, keep a copy of the file before you change it.
- Leaving the editor on “just in case”. SFTP and your host’s file manager cover the rare day you need to change code.
Frequently asked questions
Does disabling the file editor stop plugin and theme updates?
No. BetterShield’s fix refuses only the capabilities behind the code editors. Installing, updating and activating plugins and themes work as before.
Is it better to use DISALLOW_FILE_EDIT or BetterShield’s fix?
Both remove the editors. The constant lives in wp-config.php and needs file access to change. The switch needs no file edit, shows in the activity log, and turns off from the dashboard. If you already set the constant, the switch changes nothing today, though it stays in force if that line is ever removed.
Can I still edit theme and plugin files?
Yes, over SFTP, through your host’s file manager, or with your deployment tools. Only the editors inside the dashboard are removed.
Will the finding come back if I undo the fix?
Yes. With the editors back, the audit reports The dashboard file editor is enabled again, unless wp-config.php sets DISALLOW_FILE_EDIT.
Conclusion
To disable file editing in WordPress, you can add one line to wp-config.php or turn on one switch. Either way the theme and plugin editors leave the dashboard, and code changes go through SFTP or your host, where they belong. With BetterShield, the switch is also how you bring the editors back.
BetterShield is free on WordPress.org. The Hardening guide covers this fix and the other fifteen.