Sensitive Directory Check Errors
Problem
You see one of the following Sensitive Directory Check messages at Configuration () > System Health:
One or more sensitive directories are accessible from the web:
One or more of your file storage directories are accessible directly from the web. Anyone who knows or guesses a file's URL can download it, including ticket attachments, client files, and downloads:
WHMCS could not determine whether these directories are readable from the web:
This check requires you to configure the System URL.
Cause
These errors indicate that the Sensitive Directory Check found unprotected directories or encountered a problem. This check ensures that your server configuration prevents direct web access to the sensitive directories on your WHMCS installation. Direct access to these directories can allow anyone who knows or guesses a file’s URL to download it, and can cause other unexpected behavior and security-related issues.
The specific error message indicates the reason why the Sensitive Directory Check failed and the directories that may require attention.
Solution
The solution depends on which message you see and, for an exposed /vendor or other core directory, the type of server that hosts your WHMCS installation.
One or more sensitive directories are accessible from the web
The method to use to fix this error depends on the type of server you use to host your WHMCS installation:
Apache® Servers
If your server runs Apache, the included .htaccess file already protects against these problems. Verify that:
- The
.htaccessfile exists in the/vendordirectory. - The
AllowOverridesetting in your Apache configuration is not set toNone. This ensures that Apache allows.htaccessoverrides.
OpenLiteSpeed Servers
If your server runs OpenLiteSpeed, verify that you have explicitly enabled the use of .htaccess files.
Other Servers
If you use a server that does not run Apache, you must update your configuration to prohibit serving files directly from the /vendor directory.
One or more of your file storage directories are accessible directly from the web
Move the affected directory outside your public web root, or configure your web server to deny direct access to it.
- To move the directory, go to Configuration () > System Settings > Storage Settings and change the affected setting to a location outside your web server’s document root.
- To keep the current location, apply the same server-specific restrictions described above (verifying the
.htaccessfile on Apache, enabling.htaccesssupport on OpenLiteSpeed, or manually restricting access on other servers) to the custom directory.
WHMCS could not determine whether these directories are readable from the web
Check for and resolve the following issues, depending on the reason the message gives:
- If WHMCS reports that it could not write a test file, make certain that WHMCS can write to the directory.
- If WHMCS reports that a redirect prevented the request from completing, make certain your WHMCS System URL setting in the General tab at Configuration () > System Settings > General Settings matches the address that your web server actually serves WHMCS from.
- If the directory’s relationship to your web server’s document root is ambiguous, move the directory to a location where you can determine its public URL, or contact your hosting provider to confirm the mapping between your document root and the directory’s file system path.
This check requires you to configure the System URL
Configure the WHMCS System URL setting in the General tab at Configuration () > System Settings > General Settings. WHMCS uses this setting to construct the URL it tests, so it cannot run this check until the setting has a value.
Last modified: 2026 September 30