Dashboard File Editor Enabled: How to Disable It in WordPress

If BadgerScan flagged your site with "dashboard file editor is enabled", WordPress is letting administrators edit your theme and plugin PHP straight from the browser. That is convenient, but it also means one compromised or malicious admin login can run any code it likes. Here is how to switch it off with a single line in your config file.

Run the free scan

One free scan, no login. This check runs alongside DNS, email, TLS, headers, exposed files and known CVEs.

What the dashboard file editor is

WordPress ships with a built-in code editor inside the admin dashboard. You reach it under Appearance then Theme File Editor, and under Plugins then Plugin File Editor. Anyone logged in with administrator access can open those screens and edit the raw PHP of your active theme or your installed plugins, then save it, all from the browser, with no FTP or SFTP client involved.

That is what BadgerScan detected here. This is not a report that your site has been broken into, and it is not a bug. It is a default WordPress feature that is switched on, and it widens what a single administrator account is able to do. Because editing theme and plugin files means editing the code that runs your whole site, the editor is a bigger deal than it first looks.

The official WordPress hardening guidance treats turning this editor off as a standard step for a production site (WordPress.org, Hardening WordPress).

Why it is worth fixing

The concern is not the editor itself, it is what happens if an administrator login is misused. If an admin password is guessed, phished, or a trusted admin account is otherwise compromised, the file editor gives a direct way to run arbitrary code on your server. A backdoor can be pasted into a theme file and saved in seconds, with no separate server access needed. Disabling the editor removes that particular shortcut.

It also protects you from honest mistakes. A single typo saved in the editor can take a live site down, and because you are editing the running files there is no safety net. Turning the editor off nudges all code changes back onto a proper path (SFTP and version control), where they can be reviewed and rolled back.

How to fix it, step by step

The fix is one line added to your wp-config.php file, the main WordPress configuration file that sits in the root folder of your site. This removes the Theme File Editor and Plugin File Editor screens for everyone, including administrators:

  • Open wp-config.php. It lives in the top-level folder of your WordPress install, next to wp-content and wp-admin. Edit it over SFTP, or through your host's file manager. Take a quick backup copy first.
  • Find the line that reads /* That's all, stop editing! Happy publishing. */ near the bottom of the file. Your new line must go above it, because WordPress ignores anything added after that comment (WordPress.org, Editing wp-config.php).
  • On a new line above that comment, add exactly: define( 'DISALLOW_FILE_EDIT', true );
  • Save the file and upload it back if you edited a local copy. There is nothing to restart. The change takes effect on the next page load.
  • Log in to WordPress and confirm the editor is gone: the Appearance then Theme File Editor and Plugins then Plugin File Editor menu items should no longer appear.

How to verify, and how to edit files later

To confirm the fix took, run the free scan again after saving wp-config.php, or simply check the admin menu: with DISALLOW_FILE_EDIT set to true, the two editor screens disappear entirely. If they are still there, double-check that the line sits above the "stop editing" comment and that true has no quotes around it. You can run the free scan to see the finding clear on the outside view of your site. When you genuinely need to change a theme or plugin file, you can still do it over SFTP whenever you need to, so this change costs you nothing for real edits, it only closes the browser shortcut. If you want to see the rest of your WordPress exposure in one place, the WordPress vulnerability scan covers this finding alongside your other settings.

See if your WordPress file editor is exposed

Run the free BadgerScan scan to check whether your dashboard file editor is enabled, alongside your DNS, TLS, security headers and known WordPress issues, all in one plain-English report. No login, nothing to install, just the outside view of your site in under a minute.

Run a free security scan

Frequently asked questions

Does disabling the file editor stop me editing my site?

No. It only removes the in-browser Theme File Editor and Plugin File Editor. You can still edit any theme or plugin file over SFTP whenever you need to, and you can still install, update and delete plugins and themes from the dashboard as normal.

Is this finding a sign my site was hacked?

No. The dashboard file editor is on by default in WordPress, so a fresh site will show this finding until you turn it off. BadgerScan is flagging a setting to harden, not reporting a break-in. It is a calm, one-line fix.

What exactly does DISALLOW_FILE_EDIT do?

Setting define( 'DISALLOW_FILE_EDIT', true ); in wp-config.php tells WordPress to hide and block the built-in code editors for every user, including administrators. It does not affect any other admin feature.

How do I know the fix worked?

Log in and check that Appearance then Theme File Editor and Plugins then Plugin File Editor are gone from the menu, or run the free BadgerScan scan again. It is passive and read-only: it never logs in or changes anything, it just reads what is publicly visible.

Sources

  1. WordPress.org, Editing wp-config.php
  2. WordPress.org, Hardening WordPress

More from CyberBadger

BadgerScan is the website side of what we do. We're one local Hamilton and Burlington team for your whole setup, on-site nearby and remote across Canada.

Coming soon: BadgerAudit. A full, on-site cybersecurity audit, interviews, hands-on review, and a detailed report, for when a self-serve scan isn't enough. Ask us about it.