Where each application keeps its database connection details

Every website that stores anything has, somewhere in its files, four lines holding the database name, the user, the password and the host. It is the only place those things are written down, which makes it the file you open when the site stops connecting, when you move servers, or when you change a password.

The catch is that every program hides it somewhere different. Here is the list, so you do not have to hunt.

The list, by program

Program The file, and what is in it
WordPress wp-config.php, in the site root. Look for DB_NAME, DB_USER, DB_PASSWORD and DB_HOST. Just below sits $table_prefix, which also has to match the database.
Joomla configuration.php, in the root. The lines are $db, $user, $password, $host and $dbprefix.
Drupal sites/default/settings.php. It all sits inside a $databases block. That folder is usually write protected: you have to unprotect it to save, and protect it again afterwards.
Laravel and bespoke projects .env, in the project root, with DB_DATABASE, DB_USERNAME and DB_PASSWORD. It is a hidden file: the file manager only shows it if you ask.
Magento app/etc/env.php, in the db section.
PrestaShop app/config/parameters.php on recent versions, or config/settings.inc.php on older ones.
OpenCart TWO files: config.php in the root and admin/config.php. Change only one and half the site works while the other half goes blank, which costs the unwary an afternoon.
Moodle config.php, in the root, in the $CFG->dbname block.
WHMCS configuration.php. Here the password may be encrypted: do not rewrite it in plain text unless you know what you are doing.
phpBB config.php, in the root.
Not sure which program it is? In the cPanel file manager, open the site folder and sort by name. If you see wp-admin it is WordPress; administrator is Joomla; artisan is Laravel. The folder names tell you more than any guess.

How to open it and change it without breaking anything

1 Copy the file before you touch it. In the file manager, right click and choose Copy. Five seconds, and it has saved a lot of people.
2 Edit it in the panel itself, with Edit in the cPanel file manager, or over FTP with FileZilla’s View/Edit. See FTP accounts and connecting with FileZilla.
3 Change only what is between the quotes. Do not delete the quotes, and do not delete the semicolon at the end of the line. One missing semicolon leaves the site blank and does not say why.
4 Save, then open the site straight away. If it went blank, put the copy back. That is what it is for.
Careful with the editor on your own computer. A text editor that saves in a different encoding, or adds an invisible mark at the start of the file, makes the site return a blank page or a headers already sent warning. Edit in the panel, or use a proper code editor set to UTF-8 without BOM.

What this file is, from a security point of view

It is the key to your database written in plain text. Anyone who reads it reads everything the site stores. Three habits worth having:

1 Never leave renamed copies in the public folder. A wp-config.php.bak or a config.old.php stops being run by PHP and starts being served as text to anyone who guesses the name. If you need a copy, keep it outside the site folder or on your own computer.
2 Never put it in a code repository. It is the most common leak there is, and it is permanent: deleting it later does not delete the history.
3 If you suspect it was seen, change the password. In cPanel, under MySQL Databases, set a new one for that user and write it into the file in the same minute. Between the two the site is down, so do them back to back.

If the site stopped after you edited here, the list of causes is in when the site cannot connect to the database. And if what you need is to create the database and user in the first place, that is creating databases and using phpMyAdmin.

Cannot find the file, or afraid to touch it? Send us the site address and we will point at it.

Open a support ticket

SEE ALSO

Hosting plans and what each one includes

Password generator

RECOMMENDED PRODUCT

Web hosting with cPanel

Domain and SSL included, daily backups and the panel you already know. from $10.00/mo

See plans
  • 0 Users Found This Useful
Was this answer helpful?