Anything inside public_html can be served to a browser if something goes wrong: a PHP misconfiguration, a backup copy with a .bak extension, a typo in a file name. Secrets belong one level up.
Pattern 1: a PHP config file above the web root
/home/USERNAME/config/app.php
<?php
return [
'db_name' => 'acme_shop',
'db_user' => 'acme_shop',
'db_pass' => 'long-generated-password',
'smtp_pass' => 'another-generated-password',
];
In your site:
<?php
$config = require dirname(__DIR__, 3) . '/config/app.php';
dirname(__DIR__, 3) climbs from domains/yourdomain.co.uk/public_html to your home folder. Adjust the number to your structure, or use the absolute path.
Pattern 2: .env files
Frameworks read .env files. Keep them in the app folder outside public_html. Deploying a PHP application (Composer, Laravel and frameworks)
If a file must stay inside public_html
Block direct access in .htaccess:
<FilesMatch "^(\.env|config\.php|composer\.(json|lock))$">
Require all denied
</FilesMatch>
Never
- Commit secrets to a Git repository, even a private one
- Leave
config.php.bak,.env.oldorbackup.sqlinpublic_html - Email passwords to a developer in plain text — use a password manager’s sharing feature
New to Traxio? The PHP hosting page lists the PHP versions, database and tools every account gets, free for the first 30 days.