This page offers answers to common questions about default platform settings, WordPress settings, and server configuration settings. You can use this as a quick reference for many settings and how they are configured or changed.
WordPress Memory Limit
The default WordPress Memory Limit is 40MB for a single site, or 64MB for a Multisite network.
These values can be increased to a maximum of 512MB by inserting the following lines under the “WP Engine Settings” section in your wp-config.php file:
define( 'WP_MEMORY_LIMIT', '512M' );
If you want to define a separate higher or lower memory for the WordPress admin area of the site, can add the following line after the one above:
define( 'WP_MAX_MEMORY_LIMIT', '512M' );
WooCommerce recommends setting this value to at least 128MB. You are free to define whichever memory value works best for your site, as long as it does not exceed 512MB.
Maximum File Upload Size
The default maximum upload file size for sites is 50MB.
Max File Upload Size on Multisite
In additional to the above, you will need to update the network upload size.
- Login to your WordPress admin dashboard
- Click My Sites
- Select Network Admin
- Click Settings
- Locate Max upload file size
- Note that the size here is in KB
WordPress Post Revisions or autosaves store a record of each saved draft or published update for a post. This system allows a user to see the last few changes that have been made to a post. Post revisions also allow the user to restore a page or post to a previous version.
While great in theory, revisions cause the database to grow exponentially and a large database can directly impact site performance. Every WP Engine site has WordPress revisions disabled by default. It’s our recommendation to keep revisions disabled to assure optimal site speeds and use a separate editor for managing content prior to publishing.
Revisions can only be enabled by contacting Support. Revisions cannot be enabled in the wp-config.php or php.ini files, as this will be overwritten again at the server level.
- Support can help you enable up to 5 revisions for posts, but we recommend starting with 3
- Old revisions will be automatically removed after 60 days
If you migrated a site with existing revisions that you would like to preserve, reach out to support to have revisions enabled.
NOTE: This is not a retroactive change. It will not add revisions for existing posts, only allow revisions to be stored moving forward.
If you would like to clean up your database and delete any existing database revisions, the following query can be run from phpMyAdmin.
DELETE FROM wp_posts WHERE post_type = “revision”;
WP Engine does allow general WordPress emails such as password resets to be sent through WordPress. However, for sending large amounts of email such as a newsletter or email blast we require the use of an email API or an SMTP plugin.
Port 25 is blocked for all services. We highly recommend using an email service that sends email via API, or an alternative port (such as port 2525).
All WP Engine servers have TLS 1.2 and 1.3 enabled by default.
TLS 1.0 and 1.1 will be deprecated on March 31st. As TLS 1.0/1.1 deprecation is happening across the industry, we will not be offering the option for customers to defer or opt into a version lower than TLS 1.2. For a majority of customers, an update to TLS 1.2+ should not cause any noticeable impact.
Max Execution Time
max_execution_time for scripts is set to 60 seconds.
This setting can only be decreased, and cannot be increased. If you are performing a task which will take over 60 seconds to complete, the task should be broken into smaller segments and run in batches.
Max Input Vars
max_input_vars setting is 10000, indicating no more than 10,000 variables can be attached to any request. This setting cannot be adjusted, as this is set at a platform level and higher values will have negative performance implications.
NOTE: PHP 7.4 does not support .htaccess. Review our guide for alternatives.
As these are set by default, they should not need modifications. If you require changes, reach out to Support.
WP Engine has a specific set of platform-wide server modules which cannot be modified, removed, or added. To see a full list of modules, versions, and default settings, you can create a PHP Info file.
Our system administrators have already pre-configured server settings to best suit the needs of the majority of our clients. Some functions cannot be modified from site to site or in the php.ini file as they are configured at a server level.
Here are some functions that have been disabled and therefore are not able to be altered:
Most plugins are allowed on the platform, however a handful of plugins we specifically disallow as they will cause issues.
Check our updated list of disallowed plugins.
PHP Versions are regularly released and deprecated. To see which versions are currently available on the WP Engine farm and how to change versions, check out our PHP Upgrade Guide.
WP Engine uses MySQL 5.6 and MySQL 5.7. New Digital Experiences will be placed on MySQL 5.7. To learn which MySQL version you are on, please contact Support.
WP Engine does not use the
mod_security Web Application Firewall (WAF) with Apache. Instead, we use a proprietary traffic detection and blocking system among other enterprise-grade security measures. This firewall will automatically block IPs or User Agents based on a predetermined set of rules.
If you’d like to manually block an IP, User Agent or country on this firewall, reach out to our Support team for assistance.
There are several site and server-wide configuration files in place for each environment. Some files are accessible and able to be modified, while others are not.
|Configuration file||Is editable?|
|php.ini file||No. Server-wide PHP settings are unable to be changed.|
|.htaccess file||Not recommended. PHP versions 7.4 and up will not read the .htaccess file. Refer to our guide for more information.|
|wp-config.php file||Yes. This file can be edited, but there are many WP Engine-specific settings in this file which should not be changed. For the best results, put custom entries in the “WP Engine Settings” section at the bottom.|
|nginx.conf file||No. Server or site-specific Nginx settings are not able to be adjusted. If there is a specific Nginx setting you wish to adjust, please contact Support to see if there are any internal changes which may be made|
WP Engine MU Plugins
There are certain must-use plugins that you may see added to your WordPress website by WP Engine. These are added for specific reasons, such as security or functionality.
While we don’t recommend it, some of these plugins can be disabled. If you’d like to remove a WP Engine MU plugin, reach out to our Support team.
WP Engine Common
wpengine-common plugin provides most of the WP Engine platform functionality. Platform features provided by this plugin can be seen in your wp-admin dashboard under the WP Engine menu icon.
This plugin cannot be disabled, however the menu icon can be hidden with custom coding.
WP Engine Seamless Login
wpe-wp-sign-on-plugin plugin files are added for the WP Engine “Seamless Login” feature. This feature gives you the ability to securely log in to the wp-admin of a website directly from the User Portal.
To learn more about this functionality see the Seamless Login guide.
WP Engine Security Auditor
wpengine-security-auditor plugin performs two main functions:
- Log security-relevant events to the Apache error log. Examples of logged events are login, role changes, and plugin upgrades.
- Periodically calculate and log checksums for plugins, themes, and WP core files.
We do not recommend disabling this plugin as it adds security features. However, if you find too many events are being logged it can be disabled by adding the following feature flag to your
Force Strong Passwords
force-strong-passwords is added to force all users with access to the wp-admin are of your site to use strong passwords. Strong passwords are only required for Administrator, Editor, and Author roles. It is not required for “weaker” roles like Subscriber and Contributor. Our system to force a strong password only requires users to set a strong password when resetting the password from the wp-login.php page.
This plugin should never be disabled as it can create a serious security vulnerability in your website.
NEXT STEP: Learn more about .htaccess alternatives