How to stop direct URL access to files in WordPress uploads Pro

Files in wp-content/uploads are public to anyone with the link. How to block direct URL access to PDFs and other private uploads without breaking your site's images.

Updated September 26, 2026

WordPress stores uploads in wp-content/uploads as plain files, and anyone with a file’s URL can download it without WordPress running. To stop direct access, keep private files in a folder the web server refuses to serve, or outside the web root, and deliver them through a script that checks permission first.

This guide explains why uploads are public, how to check your own site, the main ways to lock files down, and how FileDeck Pro handles it for documents you restrict.

Why are WordPress uploads public by default?

When you upload a file, WordPress saves it under wp-content/uploads/, usually in a year and month folder: /wp-content/uploads/2026/09/contract.pdf. Requests for that address are answered by the web server directly, because serving static files that way is fast. WordPress doesn’t load, so no login, role or password check takes place.

That is exactly right for images, stylesheets and public downloads. It is a problem for contracts, HR policies, member resources and client files — anything where the page linking to the file is restricted but the file isn’t.

How do I check whether my files are exposed?

  1. On a page with a private document, right-click the download link and copy the link address.
  2. Open a private or incognito window, so you’re logged out, and paste the address.
  3. If the file opens or downloads, it is publicly reachable.

To see which of your PDFs a search engine has already found, search Google for site:yourdomain.com filetype:pdf.

If a plugin offloads your media to a CDN or cloud bucket, test the address your pages actually use. Rules on your own server don’t apply to files served from somewhere else — the bucket’s own settings do.

What are the ways to block direct access?

Method Stops direct downloads? Catch
Deny the whole uploads folder Yes Breaks your images and other media along with the private files
Deny a private subfolder, and serve files through a permission-checking script Yes You need the script, and moved files need new links
Store files outside the web root, and serve them through a script Yes Not all hosts allow it; migrations and backups must include the folder
Expiring signed download links Limits how long a copied link works Only meaningful on top of one of the rows above
Hotlink (referrer) protection No — it stops other sites embedding your files Browsers can omit or change the referrer
Random filenames, noindex, robots.txt No They hide a file from search; anyone with the link still gets it

The dependable pattern is the second or third row: the web server refuses direct requests, and a script inside WordPress checks each visitor’s permission before handing over the file. Expiring links are a useful addition, so a copied link stops working after a few minutes.

How do you block a private folder on Apache and nginx?

Keep private files in a dedicated subfolder, for example wp-content/uploads/private/, and deny it at the web server.

Apache reads .htaccess files. Put one inside the private folder containing:

Require all denied

nginx ignores .htaccess files, so the rule belongs in your site’s server configuration, followed by an nginx reload:

location ^~ /wp-content/uploads/private/ {
    deny all;
}

Test with the private-window check above; you should get 403 Forbidden. Many managed hosts run nginx, which is a common reason a hand-written .htaccess rule appears to have no effect. If you can’t edit the server configuration, ask your host to add the block.

Blocking is only half the job. Once the folder is denied, nobody can download from it, including the people who should. Your pages then need to link to a download script rather than the file, and the script has to:

  • check the visitor’s permission on every request, not only when the page loads;
  • read the file from disk and send it with the right headers, rather than redirecting to the file’s real address;
  • ideally, issue links that expire, so a forwarded link stops working.

How to stop direct access with FileDeck

FileDeck Pro — file protection is included in all Pro plans, from $59/yr. See pricing

FileDeck Pro provides the protected folder, the server rule and the permission-checking download route for files attached to documents you restrict. FileDeck Free publishes documents but doesn’t restrict them or move their files.

  1. Add the files as documents. Use Documents → Add New Document, or Upload files on the Documents list for a batch. See add a document.
  2. Restrict them. Edit a category under Documents → Document Categories and use Restrict to roles (FileDeck), Password protect (FileDeck) or a client area. For a single document, set Visibility in its Document File box to Logged-in users only, Author only or Specific people only. See the access control overview.
  3. FileDeck moves the file. As soon as a document is restricted, its file moves into wp-content/uploads/filedeck-protected/, a folder blocked from direct access. On Apache, FileDeck writes the blocking rule itself. On nginx, add the location block from protect files on nginx servers.
  4. Downloads go through FileDeck. The download link in your library doesn’t change. Each request is checked against the visitor’s permission, and permitted visitors get a signed link that expires after 15 minutes. See how signed download links work.
  5. Test it. In a private window, the file’s old uploads URL should no longer return the file, and a visitor with permission should still download normally from the library.

Only the files of restricted documents move. Public documents and the rest of your Media Library are served as before, so theme images keep working. Make a document public again and its file moves back to the normal uploads location.

One limit to know: a document that links to an external URL, such as a Google Drive or Dropbox file, isn’t covered by file protection. That host controls access to the file — see external files.

Pro — more controls on the same download route: hotlink protection, IP rules, single-use links, download quotas, and vault offload to serve protected files from an S3-compatible bucket by short-lived link.

What about files that are already out there?

  • Copies already downloaded stay downloaded. Blocking stops future downloads; it can’t recall a file someone already saved.
  • Old links stop working. Once a file moves, its previous URL no longer returns it, so links in old emails or search results fail. Search engines drop dead URLs over time, and their removal tools can speed that up.
  • Clear your caches. A CDN or caching plugin may keep serving a stored copy until you purge it.

FAQ

Can I block direct access to uploads with .htaccess alone?

Blocking the whole uploads folder breaks your images, and blocking a subfolder stops everyone, including permitted users, until you add a script to serve the files. .htaccess also has no effect on nginx servers. A rule on its own is half a solution.

Does robots.txt or noindex stop people downloading files?

No. They ask search engines not to crawl or list a file; anyone with the URL can still download it. A robots.txt file is itself public, so listing a private folder there points people to it.

How do I protect uploads on nginx?

Add a location block that denies the private folder to your site’s server configuration and reload nginx, or ask your host to add it. For FileDeck’s protected folder, the exact block is in protect files on nginx servers.

Will blocking direct access break my images?

Not if you block only a private folder rather than all of wp-content/uploads. FileDeck moves only the files of restricted documents, so the rest of your media is served as normal.

Does FileDeck Free block direct access to files?

No. File protection is part of FileDeck Pro, along with the access rules that decide which documents are restricted. See free vs Pro.

Next steps

For a password rather than logins, read how to password-protect file downloads. For members with accounts, see how to restrict downloads to logged-in users. Our security page sets out how file protection behaves, and you can try the library itself on the live demo.

Still stuck? Email support@getfiledeck.com.