Free tool

Explain this .htaccess

RewriteCond, [L,R=301,NC], FilesMatch… The .htaccess file controls much of how a site behaves, and almost nobody can read it. Paste yours: we explain it line by line, and flag what looks like a hack.

The file sits at the site’s root (often public_html or httpdocs). Its name starts with a dot: in the file manager or your FTP software, turn on “show hidden files”.

Examples

🔒 The file is read by your browser and is not sent anywhere.

What a .htaccess file does

On Apache and LiteSpeed servers, this small text file sets the rules for its folder and all subfolders: redirects, HTTPS, caching, access, custom error pages.

WordPress writes its own block in it, and many plugins (caching, security, SSL) add theirs, framed by # BEGIN and # END comments. A single typo and the whole site shows a 500 error: keep a copy before any change. On nginx servers, the file is ignored.

Reading a rewrite rule

RewriteCond

The conditions

“If this server variable matches this pattern”. Several conditions in a row must all be true, unless they end with [OR].

They only apply to the RewriteRule right after them.

RewriteRule

The rule

A pattern for the requested address, a destination, then flags between brackets.

$1, $2 reuse the parts captured in parentheses; %1 those of the last condition.

[L,R=301,NC]

The flags

L stop here, R=301 permanent redirect, NC ignore case, QSA keep the parameters.

Each flag is explained in the result.

What hacked .htaccess files look like

Attackers love this file: a few lines are enough to divert traffic or keep a door open, and nobody reads it. The patterns we flag:

  1. Selective redirectsOnly visitors coming from Google, or on phones, are sent to another site. The owner, who types the address directly, sees nothing.
  2. PHP where it does not belongAddHandler or SetHandler that make .jpg or .ico files run as PHP, auto_prepend_file that runs an unknown file before every page.
  3. The locked doorA <FilesMatch ".(py|exe|php)$"> block that forbids every PHP file, followed by a list of allowed files with odd names: only the attacker’s scripts still work.
  4. Additions inside the WordPress blockLines slipped between # BEGIN WordPress and # END WordPress, where nobody looks.

If a line is flagged: do not just delete it. The attacker usually left other files behind (a flagged .htaccess is often rewritten within minutes). Change every password (hosting, FTP, WordPress, database), update everything, and ideally have the site cleaned. Our flagged as dangerous? tool tells you whether Google has noticed.