The old method works for me, and any requests result in a 403 status response instead of execution of the php script. I’ve not checked your 2nd method, but if it works it will similarly respond with 403 denied/forbidden.
To test you simply have to insert the URL of your “wp-config.php” in the address bar of your browser e.g. http://example.com/wp-config.php . Depending on browser and/or sites custom 403 settings your browser will display “forbidden”, “access denied” etc.
Note you can also move wp-config.php one directory up from where WordPress installed it – and if this is then above Webroot/public_html it will no longer be “directly” accessible by hackers. More on this here Is moving wp-config outside the web root really beneficial?
Related Posts:
- Improve wordpress security by hiding non public resources
- Does this .htaccess security setting really work?
- File and directory permissions
- Rewrite /?rest_route=/ link to /wp-json/ without changing default permalink structure in apache
- index.php not loading in main folder of wordpress
- Using “wordpress_logged_in” to restrict direct access to uploads folder in 2021
- WordPress URL/Folder ReWrite using Htaccess
- Which WordPress scripts need to be executable for a fresh installation?
- Blocking access to wp-login via htaccess not working
- Attach to wp-login.php and xmlrpc.php
- Redirect from different port to subdomain – htaccess
- WordPress 404 on Subdomain
- XMLRPC filtering through htaccess not working
- Only expose routes with prefix /wp-json on WordPress using Apache
- Restricting user login by IP address
- What’s the opposite of required valid user in .htaccess authentication
- How can i redirect one url to another url using .htaccess or add_rewrite_rule
- Override htacces rule only for specific directory
- Restrict uploaded files into a custom folder to logged in users by htaccess: looking for Nginx – not only Apache – solution
- WordPress: Adding Security
- WordPress not seeing .htaccess rules
- .htaccess Security Header Rules
- mod_rewrite loop, redirecting http to https on certain section of wordpress blog
- .htaccess in subdir gets ignored by WordPress’ own .htaccess in /
- Rules in .htaccess only if the requested URL is /wp-admin
- Directing subdomain to main domain and keeping the subdomain format with .htaccess
- WordPress – Promoting A Dev Build In A Subdirectory To Production / Root Directory
- Redirect old domain with query paramaters
- Does WP suppresses .htaccess if permalinks are disabled?
- Disable directory browsing of uploads folder
- Strange behaviour of is_user_logged_in() and get_current_user_id()
- fix 302 redirection error on https
- Access sub-domain when root public_html is protected with .htaccess password
- Accepting special characters in querystring
- WordPress permalinks confusion
- Selectively Disabling PHP via .htaccess in Root Directory
- Configure .htaccess to have a WordPress single site installation with all subdomains pointing to the same pages?
- Should I prevent access to .htaccess and wp-config.php files?
- Blocking wp-login in HTACCESS has also blocked password protected pages
- Basic Auth .htaccess on wp-login, but allow logout from woocommerce
- Using htaccess to prevent spam through wp-comments-post.php
- Unable leverage Browser Caching on AWS Bitnami stack (Apache) through W3TC and Cloudfront CDN
- How to move wordpress website from hosting account to localhost
- How to block wordpress admin by htaccess
- I can access subdirectory, but not files within it
- How can I create a private site that is inaccessible from the outside?
- Restrict Content for only Contributors via .htaccess
- Allowing access to certain WordPress created pages or posts with htaccess / htpasswd
- WordPress redirection
- How To Add CSP frame ancestors in WordPress Website? [closed]
- Subfolder install not working
- Browser Caching .htaccess
- Hardening WordPress – how to set .htaccess permissions?
- Avoid duplicate content on pretty URLs with htaccess
- Why is this line of code Wrong in every WordPress .Htaccess security article?
- What’s the point of the default .htaccess?
- malware affecting backend of wordpress website-could be .htaccess file
- How to redirect all HTTP requests to HTTPS
- Default .htaccess file for WordPress?
- Which one does WordPress prioritize when it comes to php.ini, wp-config and .htaccess?
- Security and .htaccess
- How disable SSL redirect for specific URL?
- Which ways can be used to log in to WordPress?
- Why does the header set X-Robots-Tag apply to all pages?
- How to change “wp-admin” to something else without search-replacing the core?
- Error:406 not acceptable
- A plugin changes my .htaccess file and I can’t access httpd.conf as that’s a shared server
- How can I code my plugin to safely modify .htaccess?
- HTAccess stops me from accessing WordPress Dashboard links
- .htaccess rewrite rule puzzle
- browser caching not disabled after disabling in .htaccess
- Transfer to HTTPS – mixed content on main page only [closed]
- Htaccess redirect after changing Language URL format
- blocking access to all post/tag URIs via htaccess
- sitemap contains weird links and does not contain my pages [closed]
- want to rewrite an URL in wordpress
- how to redirect 301 my old search query string to wordpress search query string?
- How to block access to files without modifying .htaccess or ngnix config? [closed]
- how to combine wordpress htaccess on my root domain + php on subfolder
- Allow REST API over HTTP, the rest of the site forced to HTTPS
- Conflict with Force SSL and Rewrite Rules
- How do I do a redirect to WordPress permalink with post id via htaccess?
- Creating a copy of a website in a subdirectory, wp-admin redirect problem
- Troll the hackers by redirecting them
- I am new in word pres my font awesome is not allow
- Why my WordPress Site Asking for HTTP Authentication?
- htaccess redirects invalid request to home page not 404
- Deny php execution in /wp-includes – using .htaccess in /wp-includes VS root folder
- How to properly give WordPress its own directory
- WordPress permalinks is wrong. It wants me to change my htaccess file. But then site crashes
- Question with .htaccess and wp-login.php prevention
- WordPress RSS feed to external XML
- Does htaccess password keep search engines out?
- htaccess old php pages to new wordpress ones
- different CNAME to corresponding subfolders
- block seacrh engines for all pages EXCEPT homepage
- My WP site and password was hacked, what to do? [closed]
- htaccess – Server Subdirectory With Different Name Than URL Subdirectory
- .htaccess seems to be required but I can not find it
- cant access website thru www only works on direct xyz.com