Dear developers,

There are missing points in the current code, can you update the code and change:

  • wp-admin by WP_ADMIN_DIR
  • wp-content by WP_CONTENT_DIR
  • wp-includes by WPINC

#1 @georgestephanis
11 years ago

Howdy, and thanks for the bug report!

Could you explain how this is a security issue, in your opinion, let alone a blocker?

Also, could you refer to specific examples in the codebase that you're referring to? WPINC is a folder name, but a hardcoded constant in core, and could be used in filesystem paths and urls. WP_ADMIN_DIR isn't actually a thing, because core doesn't support relocating the wp-admin directory like it supports relocating the wp-content directory -- hence the need for WP_CONTENT_DIR -- which is the full path, not just the folder name like WPINC is.

#2 @helen
11 years ago

#3 @ocean90
11 years ago

#4 @Neustradamus
11 years ago

In the same time, by default, you can add a .htaccess in /

# Disable directory browsing
Options All -Indexes

In the code there are (not all):





I will be nice to have a WP_INCLUDES_DIR / WP_INCLUDES_URL for replace wp-includes
It will be nice to have a WP_ADMIN_DIR / WP_ADMIN_URL for replace wp-admin

#5 @SergeyBiryukov
11 years ago

Duplicate of #7194, #14157, #24368.

