Support

Admin Tools

#43347 .htaccess gets re-written by admin tools

Posted in ‘Admin Tools for Joomla!’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
5.4.8
PHP version
8.3
Admin Tools version
7.9.2

Latest post by nicholas on Sunday, 20 September 2026 08:27 CDT

[email protected]
Hi Akeeba Support, I’m having an issue with Admin Tools repeatedly restoring an older version of my site’s .htaccess file. I manually replace .htaccess with a known-good version, but after a period of time Admin Tools appears to regenerate or restore an older version. When this happens, Joomla then reports that the site is running PHP 8.1.34 and displays the following warning: “We have detected that your server is using PHP 8.1.34 which is obsolete and no longer receives official security updates by its developers. The Joomla! Project recommends upgrading your site to PHP 8.2 or later…” The hosting environment itself is configured to use a newer PHP version, so it appears that the .htaccess being restored may contain an older PHP handler or other server-specific directive. I have checked the .htaccess Maker, but I’m not intentionally clicking “Save and create .htaccess” when this happens. Could you please advise: Whether Admin Tools can automatically regenerate or restore .htaccess without manually using .htaccess Maker Which setting or feature could be causing this Whether there is a recommended way to stop Admin Tools overwriting a manually maintained .htaccess Whether PHP handler directives added by the hosting control panel should be added to the Custom .htaccess rules section in .htaccess Maker As a temporary measure I am considering making .htaccess read-only 444, but I would prefer to identify and correct the underlying Admin Tools setting. Thanks for your support!

nicholas
Akeeba Staff
Manager

Whether Admin Tools can automatically regenerate or restore .htaccess without manually using .htaccess Maker

No, it cannot do that. You would've had to go out of your way to set up an automation using Joomla CLI and the admintools:htmaker:make command provided by Admin Tools.

Whether PHP handler directives added by the hosting control panel should be added to the Custom .htaccess rules section in .htaccess Maker

Yes, absolutely! It's explicitly documented as such. See “Changing the PHP version and the .htaccess Maker” in the linked documentation page.


Now, in your particular use case, you need to figure out if the .htaccess file is being created by Admin Tools (meaning there's a rogue CRON job somewhere), or not. Here's an easy way.

Go to the .htaccess Maker. Find the “Custom .htaccess rules at the top of the file” and add the following content:

### Supercalifragilisticexpialidocious -- troubleshoot issue 43347

Save, but DO NOT create a .htaccess file just yet. Use the “Save without creating .htaccess” button in the toolbar; click the down arrow in the standard save button and you'll see that option.

What we added is a simple comment. It has no function. It merely acts as a trace maker.

When the issue repeats itself, open your .htaccess file and check it first 20 or so lines. Does the marker line exist? If it does, the file was created through Admin Tools. If not, well, Admin Tools wasn't involved.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

[email protected]
Thanks Nicholas, That is good advice I am using the timestamp comment on the top of the htaccess file produced by AdminTools to see if the htaccess gets rewritten. I dont see any custom crons apart from my akeeba backup .../joomla.php akeeba:backup:take However I believe i may have found the culprit as being the monarx security system. public_html/.htaccess.admintools was marked as "compromised" and "cleaned" it is highlighting the following: Order allow,deny Deny from all Order allow,deny Allow from all RewriteEngine On RewriteBase / RewriteRule ^index\.php$ - [L] RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule . /index.php [L] Whilst this isn't the exact .htaccess file in question I'm not sure if i am privy to the entire spectrum of the monarx defence as i don't have root access to this particular server. I have changed my "good" .htaccess privileges to 444 and so far it has not been modified again. I will raise a ticket with hosting support and ask about this scenario. I will report back with any further findings. Thank you for support.

nicholas
Akeeba Staff
Manager

The Order/Deny line pair is the standard way to tell Apache to fully disallow web access to a specific directory. This is necessary defense. Removing it makes your site less secure.

The RewriteEngine/RewriteBase/RewriteCond/RewriteRule stanza is how SEF URLs (Joomla) / permalinks (WordPress) are implemented. Disabling it breaks the site. If anything, going back to non-SEF URLs is in itself a mild security issue.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!