Accurate guidance for Steel Security Free and Steel Security Pro

Block PHP Execution in Uploads

Uploads directories should not normally execute PHP. Steel can manage this on supported server stacks and explain the manual path for others.

Hardening Free / Pro Updated August 9, 2026

Why it matters

If PHP or PHP-like files can execute from uploads, a successful file upload vulnerability can become direct code execution.

What Steel Security checks

Steel checks whether uploads execution blocking appears present and whether the current server family supports managed edits.

What Steel Security can do

On Apache and LiteSpeed, Steel manages a scoped `.htaccess` block.

On IIS, Steel manages a scoped `web.config` section.

On Nginx, Steel shows manual guidance instead of pretending it can edit server configuration safely from inside WordPress.

  • Managed apply and rollback on Apache/LiteSpeed
  • Managed apply and rollback on IIS
  • Manual guidance only on Nginx

Rollback / Recovery

Rollback removes only the Steel-managed block or section, rather than rewriting unrelated server configuration.

Continue reading