Skip to content

How to Configure Nginx for WordPress

Check Nginx WordPress with server_name, root, try_files, PHP-FPM, sensitive file restrictions, TLS, cache and log settings, and before reloading with syntax test.

Author Bipida Editorial Team Published
Share this article

Nginx configuration for WordPress must do three things right: deliver static files directly, send non-existent permalinks to the WordPress front controller, and deliver only valid PHP files to PHP-FPM. Most 404 errors, PHP downloads, redirect loops, or 502 errors come from root, location, socket, or proxy header errors.

Quick answer:Find the actual document root and PHP-FPM socket to the same server, a separate block server withserver_nameMake it right, for WordPress.try_filesDefining the PHP path to FPM. Always before reloadingnginx -tThen smoke test the page with the real host, permalink, login, upload and PHP.

Before I wrote Config.

  • Main domain and permissible aliases
  • The actual root document of WordPress
  • Web server user and permission files
  • PHP-FPM and real socket/port
  • Upload and timeout limits required for the program
  • Location of certificate and method of extension
  • There's a high-level CDN or reverse proxy.

Socket path from the active service and config the same environment, named asphp8.x-fpm.sockIt's just a placeholder and shouldn't be guessed.

A fit for the skeleton.

server {
    listen 80;
    server_name example.com www.example.com;

    root /var/www/example.com/public;
    index index.php index.html;

    location / {
        try_files $uri $uri/ /index.php?$args;
    }

    location ~ \.php$ {
        include fastcgi_params;
        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
        fastcgi_pass unix:/run/php/PHP_FPM_SOCKET;
    }
}

Domain, root, and socket are examples. Replace them with server reality before using them. This skeleton does not cover all security, TLS, cache, or multisite needs and is the starting point. Test the current configuration file to backup and change it in a staging or virtual host experiment.

server_nameAnd the default server.

Specify the permissible domains. The default server should not deliver the request of any unknown host to WordPress production. Specify the canonical hostname and redirect the alias with a limited redirect to the same domain. Direct use of the host that the user sends in the redirect can create a security issue.

Root and ownership document

rootIt's got to be a folder thatindex.phpA single-level error can cause a 404 or a structural disclosure. A web server usually requires code to be read and uploaded from the write path.777Do not open. Knowfully separate deploy user and runtime user.

Permalink withtry_files

The top order first checks the actual file and directory, and then the request is sent with the query string toindex.phpHe'll send it if he wants to.$argsIf deleted or rewritten incorrectly, the search, preview or program parameters are damaged..htaccessIt doesn't read; the rules of the plugin have to be translated separately.

Secure PHP to PHP-FPM

SCRIPT_FILENAMEIt needs to be mapped to the actual file andfastcgi_passAccess to the socket or port is enabled. The permission socket must also be compatible with the Nginx user. If there is no upstream or connection is rejected, 502 occurs. Do not change the socket with the PHP version guess.

Unwanted PHP execution blocked

Only the required routes should be accessed to PHP-FPM. The upload path should not be the place where the user script is running. The implementation of the rule depends on the site layout and location precedence; after execution, check a safe test file and request for banned routes.

Sensitive and Hidden files

Block web access to config, backup, dotfile, log and artifact deployment files. The comprehensive rule may also block the well-known path required for the certificate, so design the necessary exception carefully. secret should not be stored inside the document root even if Nginx blocks it.

Upload Size and Timeout

client_max_body_sizeThe request body ceiling is in Nginx, but PHP and WordPress have their own ceiling. Harmonize all layers with the actual need. The ceiling is very large without authentication and rate limit risk resources.

FastCGI Timeout and Buffer

Default values may be sufficient for workload. Buffer and timeout changes should be based on the response header/body and time of PHP, not the general version of the Internet. Do not hide 504 with infinite timeout; remove query, external API, or long job from the interactive request.

Static and header cache

Image, CSS, and JavaScript versions can have longer caches, but HTML, feed, and fingerprint-free files require different. The rule extension axis may stale dynamic or asset files without versions.

Page cache and WordPress

Nginx can have caches in various architectures, but cookies, login, preview, cart, and checkout must be bypassed correctly. The public personal response is a privacy risk. Design the cache key, purge, and failure behavior before activating the hit/miss header.

TLS and HTTPS redirect

Design the certificate/authentication block server and HTTPS block to fit your tool. Test the certificate chain, hostname and extension. Redirect to HTTPS should not loop, especially behind the CDN. Enable HSTS only after the domain and subdomains are ready.

Back to Reverse Proxy or CDN.

Accept the actual IP and scheme only from trusted proxies. If Nginx always imagines the origin request as HTTP, WordPress may create a redirect loop or an insecure cookie. Trusting the header of each client makes it possible to falsify IP and circumvent rules. A list of valid proxies must be maintained.

WordPress Multisite

Multisite requires different subdirectory and subdomain rewrite and DNS. Do not use single-site config blindly. Test the network type, upload path, domain mapping and cookie according to the version documentation and all sites.

Log for the defect.

Access log must record the host, status, upstream status, request time and upstream time without secret. The error log has a proper level and rotation prevents the disk from filling. Do not log the query string or sensitive header for no reason.

Accreditation and Reload

sudo nginx -t
sudo systemctl reload nginx
systemctl status nginx --no-pager

First, get a backup from the configuration. Only reload if the syntax test is successful; reload usually keeps existing connections graceful, but does not guarantee logical route accuracy.

Smoke test after reload.

  • Home page and an internal permalink
  • CSS, image and real 404.
  • In and out of the manager.
  • Upload controlled.
  • Form, cron and REST API required
  • HTTPS, canonical redirect and domain alias
  • Cart, checkout and callback for the store.

Performance reviews

Before and after, compare TTFB, p95, status, CPU, memory, PHP queue, and upstream time with a fixed scenario.The PHP-FPM setting guideFollow him.

Common Mistakes

  • Guess the PHP socket.
  • Copy the config without root compatibility.
  • Expecting the effects of.htaccess
  • Recharge withoutnginx -t
  • Caching the personal page.
  • Trust the proxy header of all.
  • Too much timeout to hide the slow.
  • License.777For the 403 solution.

Nginx or Apache?

If the choice hasn't been made yet,Compare Nginx and ApacheMigration simply for speed claims, without benchmarks and rules conversion, may make more mistakes.

When do you need special assistance?

If a site has a complex store, multisite, CDN or security rule, public configuration is not enough and an error can interrupt login or payment.Install and configure the Linux serverIt can configure Nginx, PHP-FPM, TLS, log and rollback based on the actual architecture.

Common Questions

Why are there 404 internal links after you install Nginx?

Usually the front-controller rewrite ortry_filesIt's missing; check the root and the active configuration.

Why is the PHP file downloaded?

The PHP handler is not active or the request is not sent to the FPM. Immediately correct the site from external exposure and config.

Why is Nginx giving 502 error?

Check socket/port, permission, PHP-FPM status and upstream log; don't guess the name of the socket.

Should I copy Config ready for the Internet?

No, the root, the version, the socket, the proxy and the security requirements are different.

Nginx vs. Apache: Architecture, Compatibility, and Operating Cost
Compare Nginx and Apache in terms of processing model, static file, PHP, rewrite,.htaccess, reverse proxy, security and team capabilities, and choose wisely.