All Tools View Categories About Contact Privacy

Nginx WordPress-Optimized Config Generator

Serve WordPress on nginx with safe PHP-FPM routing and locked paths.

Runs entirely in your browser - nothing is uploaded and no cloud connection is made.
Your WordPress server block will appear here.
-
lines
-
blocks
-
locations

About Nginx WordPress-Optimized Config Generator

WordPress on nginx needs a specific shape: PHP requests routed to FPM, permalinks resolved through a front-controller try_files, and sensitive files like wp-config.php and .htaccess kept out of direct reach. A common failure is a WordPress install that returns 404 on every post because try_files is wrong, or a config that accidentally serves wp-config.php to the world. The Nginx WordPress-Optimized Config Generator builds a hardened server block and validates the result before you copy it.

At the heart of the configuration are a handful of directives. try_files resolves WordPress permalinks by falling back to index.php with the query string. fastcgi_pass sends PHP requests to the WordPress PHP-FPM upstream. location wp-config exact-match block that denies web access to the credentials file. location ht denies access to Apache .htaccess files that are meaningless on nginx. index sets index.php as the directory entry point WordPress expects. root points nginx at the absolute WordPress install directory. include (fastcgi-php.conf) loads the FastCGI parameters PHP requires. Together they shape how the server behaves, and the tool assembles them in the right context so the result is valid on the first try.

Common mistakes are easy to make. Wrong try_files breaks every permalink and returns 404; the generator uses the canonical WordPress fallback. Leaving wp-config.php reachable exposes database credentials, so the block denies it explicitly. A bad FPM socket or non-absolute root fails at reload, so both are validated before output. The generator anticipates each of these and either sets a safe default or rejects the input with a clear message before anything is written to your clipboard.

Validation is strict because small configuration errors fail in subtle ways. Every input is checked for plausibility, and after the block is assembled it is re-parsed by a built-in tokenizer so unbalanced braces, missing semicolons or stray characters cannot reach your clipboard. Stat cards report line and block counts, and copy, download and print exports are one click away. Everything runs in your browser; nothing you type is transmitted to any server.

In practice this block drops into any standard nginx install. Save the output as a file under /etc/nginx/conf.d/ (or sites-available with a symlink), run nginx -t to confirm the syntax, then reload with nginx -s reload. Because the generator emits a single, self-contained server block with no hidden dependencies, it composes cleanly with your existing caching, logging and security configuration without directive collisions.

Beyond producing correct config, the tool is a reference you can read back and learn from. Each control maps to a real nginx directive, the sample button shows a complete working block in seconds, and clearing the form resets every field to its safe default. Standardising on a generator like this removes per-developer variation, keeps your configuration readable, and gives you a repeatable, auditable setup that passes nginx -t on the first try.

When something looks wrong in production, the first move is always to re-run nginx -t and inspect /var/log/nginx/error.log; most failures surface there with a line number. The access log records every request, so a sudden spike or a wall of 499 responses points straight at backend or timeout problems the generator helps you avoid in the first place.

This server block is designed to sit alongside - not fight - your other configuration. Because it declares its own server_name and a single, self-contained set of directives, you can drop it into conf.d without worrying about collisions with global caching, logging or security snippets that live elsewhere in the nginx tree.

For a production site, pair this block with TLS termination: serve on 80 for the redirect or health checks, and place the encrypted listener (or a front-end load balancer / CDN) in front so clients always speak HTTPS. The generator keeps that boundary clean so the two layers compose instead of overlapping.

If a change ever needs to be undone, the output is plain text you control: delete the file from conf.d, re-run nginx -t, and reload. There is no database and no hidden state, so rolling back is as simple as restoring the previous version from version control or your own backup.

Performance and correctness both benefit from explicit configuration. Defaults baked into the generator reflect current best practice rather than decades-old forum snippets, so the block you ship today will not surprise you with deprecated directives or insecure fallbacks six months from now.

For teams, a generated block is also documentation. New engineers can read the exact directives in place, compare them against the sample, and learn the relevant nginx behaviour without reverse-engineering a hand-maintained file that drifted from its original intent.

Features

  • try_files - resolves WordPress permalinks by falling back to index.php with the query string.
  • fastcgi_pass - sends PHP requests to the WordPress PHP-FPM upstream.
  • location wp-config - exact-match block that denies web access to the credentials file.
  • location ht - denies access to Apache .htaccess files that are meaningless on nginx.
  • index - sets index.php as the directory entry point WordPress expects.
  • root - points nginx at the absolute WordPress install directory.
  • include (fastcgi-php.conf) - loads the FastCGI parameters PHP requires.
  • Self-verifying output re-parsed before display.
  • Copy, Download and Print exports.
  • Load-sample button fills realistic values.
  • Statistics cards for quick checks.
  • Runs entirely in your browser - nothing uploaded.

How to Use

  1. Enter the public domain the blog serves.
  2. Set the absolute WordPress document root.
  3. Enter the PHP-FPM upstream as unix:/path/sock or host:port.
  4. Click Generate (or Load sample) and review the block.
  5. Drop it into conf.d, run nginx -t, then reload.
  6. Visit the site and confirm permalinks and the admin area work.

Examples

Example 1 - Standard WP domain, root and a Unix FPM socket produce a clean WP block.

Example 2 - Permalinks try_files routes pretty URLs to index.php.

Example 3 - Locked wp-config wp-config.php is denied to the public.

Example 4 - Bad root rejected a relative root is reported before generation.

Example 5 - Bad socket rejected an invalid FPM upstream is caught up front.

Benefits

  • Canonical WordPress try_files for permalinks.
  • wp-config.php and .htaccess locked down.
  • Correct PHP-FPM routing with validated socket.
  • Self-checked output re-parsed before display.
  • Stat card shows location counts.
  • Private: everything runs in your browser.

Frequently Asked Questions

Why the permalink try_files?
WordPress uses front-controller routing, so unknown URIs must fall back to index.php with the query string intact.
Why deny wp-config.php?
wp-config.php holds database credentials; denying direct web access is a baseline hardening step.
What about .htaccess?
Apache-style .htaccess files do nothing on nginx, so the generator denies access to them to avoid leaking config.
Do I need caching?
This block is a clean, correct baseline; add a page-cache layer such as the caching config generator for high traffic.
Which PHP-FPM socket?
Match your pool, commonly unix:/run/php/php8.2-fpm.sock; the tool only references it.
How do I enable HTTPS?
Put a TLS server block in front or run this behind a TLS-terminating proxy; the generator emits plain HTTP by design.
Is the output validated?
Yes - the block is re-parsed by a built-in tokenizer before display.
Is anything uploaded?
No. All generation runs locally in your browser.