Skip to content
Linux

Nginx Server Block Generator

Production-ready Nginx server blocks for WordPress/PHP-FPM, static sites and reverse proxies – HTTPS, HTTP/2, www redirect and security headers included.

Runs in your browser – nothing is sent or stored.

Generate a clean, production-ready Nginx server block for a WordPress site, a PHP app, a static site or a reverse proxy in front of Node, Python or Docker. HTTPS with Let’s Encrypt paths, HTTP/2, a canonical www redirect, security headers, gzip, caching for static files and rules that block hidden files, backups and logs are built in.

Why these defaults

  • Backups, .sql dumps and debug.log files left in the web root are one of the most common data leaks – the deny rules stop them being downloaded.
  • xmlrpc.php is blocked for WordPress: it is rarely needed and widely abused for brute-force attacks.
  • PHP is never executed from the uploads folder, so an uploaded file can’t become a backdoor.

Always test first

Run sudo nginx -t before every reload. A syntax error in one site’s file stops Nginx from reloading – and on a shared server that affects every site.

Frequently asked questions

Where do I put the file?

Save it as /etc/nginx/sites-available/<domain>.conf, link it into sites-enabled, then run sudo nginx -t and sudo systemctl reload nginx.