Sensitive Directory Check Errors

Problem

This information only applies to self-hosted WHMCS installations. WHMCS Cloud handles the installation and initial configuration process for you automatically.

You see one of the following Sensitive Directory Check messages at Configuration () > System Health:

One or more sensitive directories are accessible from the web: 
One or more of your file storage directories are accessible directly from the web. Anyone who knows or guesses a file's URL can download it, including ticket attachments, client files, and downloads:
WHMCS could not determine whether these directories are readable from the web:
This check requires you to configure the System URL.

Cause

These errors indicate that the Sensitive Directory Check found unprotected directories or encountered a problem. This check ensures that your server configuration prevents direct web access to the sensitive directories on your WHMCS installation. Direct access to these directories can allow anyone who knows or guesses a file’s URL to download it, and can cause other unexpected behavior and security-related issues.

The specific error message indicates the reason why the Sensitive Directory Check failed and the directories that may require attention.

Solution

The solution depends on which message you see and, for an exposed /vendor or other core directory, the type of server that hosts your WHMCS installation.

For more information, see Enhancing Security.

One or more sensitive directories are accessible from the web

The method to use to fix this error depends on the type of server you use to host your WHMCS installation:

Apache® Servers

If your server runs Apache, the included .htaccess file already protects against these problems. Verify that:

  • The .htaccess file exists in the /vendor directory.
  • The AllowOverride setting in your Apache configuration is not set to None. This ensures that Apache allows .htaccess overrides.
For additional steps to troubleshoot Apache servers, see Apache’s documentation.

OpenLiteSpeed Servers

If your server runs OpenLiteSpeed, verify that you have explicitly enabled the use of .htaccess files.

For more information, see OpenLiteSpeed’s documentation.

Other Servers

If you use a server that does not run Apache, you must update your configuration to prohibit serving files directly from the /vendor directory.

We develop and validate WHMCS for use on Apache servers.
For steps to restrict access on other servers that use NGINX®, see Restrict NGINX Directory Access.

One or more of your file storage directories are accessible directly from the web

Move the affected directory outside your public web root, or configure your web server to deny direct access to it.

  • To move the directory, go to Configuration () > System Settings > Storage Settings and change the affected setting to a location outside your web server’s document root.
  • To keep the current location, apply the same server-specific restrictions described above (verifying the .htaccess file on Apache, enabling .htaccess support on OpenLiteSpeed, or manually restricting access on other servers) to the custom directory.

WHMCS could not determine whether these directories are readable from the web

Check for and resolve the following issues, depending on the reason the message gives:

  • If WHMCS reports that it could not write a test file, make certain that WHMCS can write to the directory.
  • If WHMCS reports that a redirect prevented the request from completing, make certain your WHMCS System URL setting in the General tab at Configuration () > System Settings > General Settings matches the address that your web server actually serves WHMCS from.
  • If the directory’s relationship to your web server’s document root is ambiguous, move the directory to a location where you can determine its public URL, or contact your hosting provider to confirm the mapping between your document root and the directory’s file system path.

This check requires you to configure the System URL

Configure the WHMCS System URL setting in the General tab at Configuration () > System Settings > General Settings. WHMCS uses this setting to construct the URL it tests, so it cannot run this check until the setting has a value.

Last modified: 2026 September 30