Storing configuration and secrets outside public_html

Keep database passwords, API keys and SMTP credentials out of the web root with config files above public_html, .env files and protective .htaccess rules.

How-to guideIntermediate2 min readUpdated

Anything inside public_html can be served to a browser if something goes wrong: a PHP misconfiguration, a backup copy with a .bak extension, a typo in a file name. Secrets belong one level up.

Pattern 1: a PHP config file above the web root

/home/USERNAME/config/app.php
<?php
return [
    'db_name' => 'acme_shop',
    'db_user' => 'acme_shop',
    'db_pass' => 'long-generated-password',
    'smtp_pass' => 'another-generated-password',
];

In your site:

<?php
$config = require dirname(__DIR__, 3) . '/config/app.php';

dirname(__DIR__, 3) climbs from domains/yourdomain.co.uk/public_html to your home folder. Adjust the number to your structure, or use the absolute path.

Pattern 2: .env files

Frameworks read .env files. Keep them in the app folder outside public_html. Deploying a PHP application (Composer, Laravel and frameworks)

If a file must stay inside public_html

Block direct access in .htaccess:

<FilesMatch "^(\.env|config\.php|composer\.(json|lock))$">
  Require all denied
</FilesMatch>

Never

  • Commit secrets to a Git repository, even a private one
  • Leave config.php.bak, .env.old or backup.sql in public_html
  • Email passwords to a developer in plain text — use a password manager’s sharing feature

New to Traxio? The PHP hosting page lists the PHP versions, database and tools every account gets, free for the first 30 days.

Popular

Tip: press / to search from any pageSee all results