Common causes
- Options +FollowSymLinks in .htaccess on a cPanel host that only allows SymLinksIfOwnerMatch
- AllowOverride is set without Options, for example AllowOverride FileInfo AuthConfig
- AllowOverride Options=Indexes,MultiViews allows only specific options and your file sets another
- Options -Indexes or +ExecCGI added by a plugin, script installer or copied snippet
- A migrated .htaccess written for a server with AllowOverride All
How to fix it
- Find the Options line. Open .htaccess in the folder named in the error log and look for every Options line, including in subfolders like wp-content/uploads.
- Use SymLinksIfOwnerMatch on shared hosting. Replace Options +FollowSymLinks with Options +SymLinksIfOwnerMatch. Most cPanel hosts allow it, and mod_rewrite works with either.
- Remove options the host forbids. If Options -Indexes is not allowed, remove the line and add an empty index.html to the folder instead, or ask the host to disable directory listing.
- Adjust AllowOverride on a VPS. In the vhost's <Directory> block, add Options to AllowOverride (or list allowed ones: AllowOverride FileInfo AuthConfig Options=Indexes,SymLinksIfOwnerMatch). Run apachectl configtest and reload.
- Prefer the main config. On servers you control, set Options in the vhost instead of .htaccess; it is faster and avoids the override check entirely.
.htaccess and Apache vhost
# .htaccess on shared hosting
Options +SymLinksIfOwnerMatch
RewriteEngine On
# Apache vhost on a VPS
<Directory /var/www/example.com/public>
Options -Indexes +SymLinksIfOwnerMatch
AllowOverride FileInfo AuthConfig Indexes Options=Indexes,SymLinksIfOwnerMatch
Require all granted
</Directory> How to stop it happening again
- Use SymLinksIfOwnerMatch in .htaccess files you ship to clients
- Test copied snippets on staging before production
- Keep server-wide Options in the vhost config, not .htaccess