WordPress Directory Browsing Forbidden How to Enable
A Complete Fix Guide
If you see a 403 Forbidden, Directory browsing forbidden, or similar message when trying to access a WordPress folder, it can be confusing. You may wonder whether WordPress is broken, your hosting account is blocking access, or a file has been configured incorrectly.
The good news is that directory browsing and directory access are two different things. In many cases, WordPress itself is not the problem. The web server may simply be configured to prevent visitors from viewing the contents of a folder.
In this guide, we’ll explain wordpress directory browsing forbidden how to enable it safely, when directory browsing should remain disabled, and how to troubleshoot Apache, `.htaccess`, permissions, and index-file issues.

The Core Basics
Before changing anything, it helps to understand what directory browsing actually means.
Normally, when you visit something like:
`https://example.com/wp-content/uploads/`
the server looks for a default file such as `index.php` or `index.html`.
If there is no index file and directory listing is enabled, the server may display a list of files and folders. This is called directory browsing, directory listing, or auto-indexing.
If directory browsing is disabled, the server can instead return an error such as:
* 403 Forbidden
* Directory browsing forbidden
* Index of / — forbidden
* You don’t have permission to access this resource
This is often intentional.
Directory browsing can expose filenames, backup files, documents, images, scripts, and other information that you may not want publicly visible. For that reason, many WordPress hosting environments disable directory listings by default.
There is also an important distinction between accessing a specific file and browsing a directory. A server may allow:
`https://example.com/wp-content/uploads/photo.jpg`
while blocking:
`https://example.com/wp-content/uploads/`
That behaviour is usually normal.
💡 WP Fix It Co Recommendation: If you’re troubleshooting wordpress directory browsing forbidden how to enable, a fast, secure WordPress host such as Hostinger can help prevent server-related problems and make implementing a safe directory configuration much smoother. Get Hostinger WordPress Hosting here.
How to Enable WordPress Directory Browsing
1. Decide Whether You Actually Need Directory Browsing
The first question is whether directory browsing should be enabled at all.
For most WordPress websites, the safest option is to leave directory browsing disabled.
You might need it if you are deliberately creating a public file repository, development environment, image directory, download area, or another application where visitors need to see a directory listing.
If you’re simply trying to fix a WordPress page returning 403 Forbidden, enabling directory browsing may not be the correct solution.
First determine why the server is returning the error.
2. Check for an Index File
One common reason a directory produces an error is that it doesn’t contain a default index file.
For example, a folder might contain:
`/wp-content/my-files/`
but have no:
`index.php`
or:
`index.html`
Depending on your server configuration, requesting that folder may result in a 403 response.
If the folder is supposed to contain a WordPress page, check whether the required index file exists.
You can use your hosting File Manager or FTP client to inspect the directory.
3. Check the `.htaccess` File
On Apache-based WordPress hosting, `.htaccess` can control directory behaviour.
A directive such as:
“`apache
Options -Indexes
“`
tells Apache not to display a directory listing when no index file exists.
If you deliberately want to enable directory browsing, you can use:
“`apache
Options +Indexes
“`
However, do not blindly change this on your production WordPress website.
Before modifying `.htaccess`, download a backup copy. A small syntax error can cause a 500 Internal Server Error.
If your hosting environment does not permit the `Options` directive, attempting to use it may also produce a server error.
4. Locate `.htaccess` in Your WordPress Installation
The `.htaccess` file is normally located in your WordPress root directory.
Typical files include:
“`text
wp-admin
wp-content
wp-includes
index.php
wp-config.php
.htaccess
“`
Remember that `.htaccess` is a hidden file on many hosting control panels.
If you cannot see it, enable Show Hidden Files in your hosting File Manager.
Make a backup before editing it.
5. Enable Indexes Carefully
If you have confirmed that directory listing is genuinely required, add:
“`apache
Options +Indexes
“`
Save the file and then revisit the directory URL.
For example:
`https://example.com/downloads/`
If the server permits directory indexing and there is no index file, Apache may now display the files inside that directory.
If you immediately receive a 500 Internal Server Error, remove the directive and contact your hosting provider.
Your server may not allow this configuration at the `.htaccess` level.
6. Check File and Folder Permissions
Incorrect permissions can also cause 403 Forbidden errors.
A common WordPress configuration uses:
* 644 for files
* 755 for directories
Avoid making everything `777`.
Although 777 may appear to solve some permission problems, it gives excessive write permissions and can create security vulnerabilities.
If only one particular folder is producing the error, compare its permissions with other functioning directories.
7. Check WordPress Security Plugins
Security plugins can sometimes restrict access to files and directories.
If the problem started immediately after installing or configuring a security plugin, temporarily review its settings.
Look for features involving:
* Directory protection
* File access restrictions
* XML-RPC protection
* IP blocking
* Firewall rules
* Hotlink protection
* Login protection
* File permissions
Don’t permanently disable important security protections just to make directory browsing work.
8. Check Your Hosting Configuration
Sometimes `.htaccess` isn’t responsible.
Your hosting provider may have directory listing disabled at the Apache or server level.
On some servers, the configuration may be controlled in the main Apache configuration rather than through an individual site’s `.htaccess`.
In that situation, changing WordPress files won’t fix the problem.
Contact your host and ask whether directory indexing is permitted for your account and domain.
This is particularly important if you are using managed WordPress hosting or a server configuration where customers cannot change Apache directives.
9. Check Nginx Configuration
If your WordPress website uses Nginx rather than Apache, `.htaccess` doesn’t control the server.
Nginx uses its own configuration files and can use the `autoindex` directive.
A configuration can look conceptually like:
“`nginx
location /downloads/ {
autoindex on;
}
“`
However, Nginx configuration is normally controlled by the server administrator or hosting provider.
Do not paste Nginx configuration into `.htaccess`.
10. Test the Directory Again
After making a change, clear your browser cache and test the directory in a private/incognito browser window.
If you’re using a caching plugin or CDN, clear its cache as well.
Then check whether:
* The directory listing appears
* Specific files still open
* WordPress pages work normally
* You receive a 403 error
* You receive a 500 error
If enabling directory indexing causes another problem, reverse the change immediately.
Best Practices and Pro Tips
For most WordPress websites, disabled directory browsing is preferable.
If visitors don’t need to see a directory’s contents, there is little reason to expose the listing.
A few useful practices:
* Keep `Options -Indexes` enabled where appropriate.
* Don’t use `777` permissions as a quick fix.
* Back up `.htaccess` before editing it.
* Keep WordPress, themes and plugins updated.
* Remove old backups and unused files from publicly accessible folders.
* Don’t store sensitive documents inside publicly accessible directories.
* Use HTTPS throughout your website.
* Test configuration changes after making them.
If you only need visitors to access individual files, direct file URLs are generally preferable to exposing the entire directory.
Common Mistakes to Avoid
Enabling Browsing Everywhere
Don’t add `Options +Indexes` globally without understanding its effect. You could unintentionally expose files in multiple directories.
Editing `.htaccess Without a Backup
A single incorrect directive can cause a 500 error. Always save a working copy first.
Using 777 Permissions
This is an overly permissive solution and can introduce unnecessary security risks.
Assuming WordPress Causes the Error
A 403 directory error is often generated by the web server rather than WordPress itself. Check hosting, permissions and server configuration before changing WordPress core files.
Conclusion
Understanding wordpress directory browsing forbidden how to enable starts with recognising that directory browsing is a server feature, not a standard WordPress feature.
If you genuinely need directory listings, Apache may allow you to enable them with `Options +Indexes`, while Nginx uses its own configuration. However, directory browsing can expose files and should normally remain disabled unless there is a specific reason to turn it on.
If your real problem is a 403 Forbidden error, investigate permissions, `.htaccess`, security plugins, index files and hosting configuration before enabling directory listings.
For more practical WordPress troubleshooting guides, fixes and beginner-friendly technical advice, keep following WP Fix It Co.