Removed access to .htaccess for admin role
-
Hi team,
Looking at your recent change log you have removed access to .htaccess for the fear of abuse. This doesn’t make sense for roles under Admin.
Why not put an Admin role behind a password wall? Or allow to add a password to specific file types or folders in any role that is managed under Admin?
It seems backwards to remove this and ask people to log in through FTP to access .htaccess. Doesn’t that make your plugin redundant. Anyone can access wp-config.php in your plugin and completely take down the site that way, which can cause more damage compared to the misuse of .htaccess alone.
Please revisit this and add another level of security i.e. password protection, rather then taking features away.
The topic ‘Removed access to .htaccess for admin role’ is closed to new replies.