Skip to content
WP Cloud
WP Cloud
    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management
    • PanelAlpha Integration: White-Label WordPress Control Panel for Hosts
    • EasyEngine Panel Integration: Visual WordPress Management for WP Cloud
    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
    • Pressable
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Impressive Hosting
    • Blog
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗
  • Solutions

    • For Hosts
    • For Agencies
    • For Registrars
    • For Native Hosting
    • Featured Partners

    Features

    • Performance
    • Security
    • Real-Time Automated Failover
    • Vertical Scaling and Bursting
    • WordPress Management

    Integrations

    • PanelAlpha Integration
    • Easy Engine Panel Integration

    Resources

    • FAQs
    • WP Cloud API
    • Partner Portal
    • Documentation
    • New Partner Guide
  • Case Studies
    • PressableA case study about how WP Cloud supports Pressable to power millions of page views daily.
    • Convesio
    • Porkbun
    • PanelAlpha
    • Ivapix
    • UNC Greensboro
    • Newspack
    • Inverse Paradox
  • Insights
    • Podcast
    • BlogWP Cloud blog page with latest news and updates about the platform.
    • Performance Benchmarks
  • Connect With Us
  • Login ↗
Start Here ↗

Browse

    • WP Cloud platform overview
    • Onboard and launch with WP Cloud
    • WP Cloud Partner Portal
    • Get support from WP Cloud
    • WP Cloud glossary
    • Manage and secure API keys
    • Client SSH
    • WP Cloud API quick start
    • Webhooks
    • Run bulk tasks across sites
      • Manage site domains and aliases
      • Domain verification records
      • TLS certificates
      • Manage custom TLS certificates
      • Cloudflare and WP Cloud
    • Clone a site
    • Configure resources, site type, and billing with site meta
    • Delete a site
    • Persistent data
    • Staging sites
    • Migrate a site to WP Cloud
      • SSH and SFTP access models
      • Client SSH
      • User SSH and SFTP access
      • Database credentials
      • phpMyAdmin
      • ABSPATH
      • Default wp-config.php
      • Site constants
      • Configure redirects and headers with custom-redirects.php
      • Akismet and Jetpack
      • Blocked and unsupported plugins
      • PHP lifecycle and supported versions
      • Symlinks and managed software
      • WordPress versions
      • Install Composer and WP-CLI packages
      • Manage platform software with WP-CLI
      • Useful WP-CLI commands
    • Transactional email
    • WordPress multisite
    • Cron scheduling
    • Decoupled and headless WordPress
    • Repair Yoast indexables
      • Page Cache
      • Edge Cache
      • Object Cache
      • Image transformation
      • Offload image sub-sizes
    • Configure lightweight 404s for static files
      • DDoS protection
      • Defensive Mode
      • Rate limiting
      • Network and web application firewalls
      • Bot protection
      • Password protection
      • HTTP and security headers
      • PHP filesystem access permissions
      • Scan a site for malware
    • Backups overview
    • Create an on-demand backup
    • Restore a backup
    • Jetpack backups
      • Error logs
      • Web server logs
    • Metrics
    • Application performance monitoring
    • Automated failover
    • IP ranges
    • Origin and edge servers
    • Server specifications and settings
    • EasyEngine integration
    • PanelAlpha integration
      • White labelling and co-marketing WP Cloud
      • WP Cloud logos
      • Terms of Service & Compliance
      • Prohibited content
      • Copyright infringement and takedown notifications
    • WP Cloud billing
    • WP Cloud for agencies and site networks
    • WP Cloud partner support options
    • Troubleshoot Page and Edge Cache
    • Troubleshoot HTTP 429 and 599 errors
    • WP Cloud HTTP status codes
    • Troubleshoot site performance
    • Cache slow database queries
    • Troubleshoot duplicate core files, wp-config.php, and wp-admin 403 errors
    • Troubleshoot email delivery
    • Troubleshoot PDF thumbnail generation
    • Troubleshoot TLS certificate provisioning
Documentation/WordPress on WP Cloud/WordPress configuration/Configure redirects and headers with custom-redirects.php

Configure redirects and headers with custom-redirects.php

LAST UPDATED

3 months ago

    WP Cloud loads an optional custom-redirects.php file before WordPress for requests handled by PHP. A site can use this file for redirects, response headers, or narrowly scoped access rules without loading WordPress first.

    Avoid custom-redirects.php when another supported platform, WordPress, or web-server configuration can produce the same result. Use it sparingly and test every change thoroughly. Planned Edge Rules functionality is intended to replace most custom-redirects.php use cases.

    Create custom-redirects.php in the site’s htdocs directory and begin the file with <?php. Test every change while logged out and with Page Cache and Edge Cache enabled. A redirect or header can be cached and affect more visitors than the original request.

    The examples below are illustrative pseudocode, not an exhaustive set of production-ready rules. Partners and site owners use them at their own risk and are responsible for adapting and testing them. The file can support other redirects, file and path handling, and response headers. Several compatible rules can share the file, but each rule should send its response and call exit when no later code should run.

    Redirect one path

    <?php
    
    if ( '/subdir' === $_SERVER['REQUEST_URI'] ) {
        header( 'HTTP/1.1 301 Moved Permanently' );
        header( 'Location: /subdir-new' );
        exit;
    }Code language: HTML, XML (xml)

    Use a temporary status while testing when browsers or caches should not retain the redirect. Change it to a permanent redirect only after confirming the destination.

    Add response headers

    header( 'X-Content-Type-Options: nosniff' );
    header( 'X-Frame-Options: SAMEORIGIN' );
    header( 'Referrer-Policy: no-referrer-when-downgrade' );Code language: JavaScript (javascript)

    WP Cloud sets the base HTTP Strict Transport Security header. Manage its includeSubDomains behavior with the HSTS subdomain endpoint. Do not attempt to replace the platform HSTS header in custom-redirects.php.

    Redirect a site’s home page

    HTTP_HOST contains a hostname, not a URL scheme:

    if (
        'example.com' === $_SERVER['HTTP_HOST']
        && '/' === $_SERVER['REQUEST_URI']
    ) {
        header( 'HTTP/1.1 301 Moved Permanently' );
        header( 'Location: https://destination.example/news' );
        exit;
    }Code language: PHP (php)

    Limit a path by country

    WP Cloud makes the request country available as an ISO 3166-1 alpha-2 code in GEOIP_COUNTRY_CODE. This example allows requests from the United States and Canada. It bypasses the check for WP-CLI, where no browser request exists.

    $allowed_countries = array( 'US', 'CA' );
    
    if ( 'cli' === PHP_SAPI ) {
        return;
    }
    
    $country_code = $_SERVER['GEOIP_COUNTRY_CODE'] ?? 'Unknown';
    
    if ( ! in_array( $country_code, $allowed_countries, true ) ) {
        header( 'HTTP/1.1 404 Not Found', true, 404 );
        exit;
    }Code language: PHP (php)

    Country detection is not an identity or authentication control. Use it only for a geographic access policy that can tolerate imperfect location data.

    Block a file or directory pattern

    if ( false !== strpos( $_SERVER['REQUEST_URI'], '/private-export/' ) ) {
        http_response_code( 410 );
        exit;
    }Code language: PHP (php)

    Limit a path by IP address

    $allowed_ips = array( '192.0.2.10', '198.51.100.20' );
    
    if (
        false !== strpos( $_SERVER['REQUEST_URI'], '/sandbox' )
        && ! in_array( $_SERVER['REMOTE_ADDR'], $allowed_ips, true )
    ) {
        header( 'HTTP/1.0 403 Forbidden' );
        echo '403 Forbidden';
        exit;
    }Code language: PHP (php)

    Replace the documentation-only addresses with the exact trusted addresses. Do not use a broad range when the service can provide stable individual IPs.

    Previous Site constants
    Next Akismet and Jetpack

    Related Guides

    • ABSPATH

      Understand why ABSPATH points to managed WordPress core on WP Cloud and use WP_CONTENT_DIR for…

      1 Min.

      READ

    • Default wp-config.php

      Recreate the default WP Cloud wp-config.php structure without replacing managed database settings.

      1 Min.

      READ

    • Site constants

      Use WP Cloud PHP constants to identify the platform, Atomic Site ID, and host client…

      1 Min.

      READ

    On this page

      Contact support

      Contact us with Support issues and questions related to WP Cloud, the WP Cloud Atomic API, API-key IP allow list changes, Station, and more.

      Check the FAQs

      Have questions? Please visit our FAQ to learn more.

      An Automattic venture

      Work With Us

      Press

      Privacy Policy

      © 2021-2026 Automattic Inc.

      Notifications