Skip to main content

WordPress Robots.txt — Setup Guide

WordPress doesn't create a physical robots.txt file by default, but it will serve a virtual one if you visit /robots.txt. Here's how to create a proper robots.txt for your WordPress site. For a general overview, see our guide to creating a robots.txt file.

Default WordPress behavior

If you visit yourdomain.com/robots.txt and haven't created a physical file, WordPress will serve a virtual robots.txt that looks like this:

User-agent: *
Disallow: /wp-admin/
Allow: /wp-admin/admin-ajax.php

This is a minimal configuration. It blocks the admin area but doesn't include a sitemap directive or block other low-value pages.

Recommended WordPress robots.txt

For most WordPress sites, this configuration provides a good balance of crawl efficiency and content discovery:

User-agent: *
Disallow: /wp-admin/
Allow: /wp-admin/admin-ajax.php
Disallow: /search/
Disallow: /?s=
Disallow: /wp-json/
Disallow: /wp-login.php

Sitemap: https://yourdomain.com/sitemap.xml

What each rule does

  • Disallow: /wp-admin/ — Blocks the admin dashboard (crawlers don't need to see login pages)
  • Allow: /wp-admin/admin-ajax.php — Permits access to AJAX functionality that themes and plugins depend on
  • Disallow: /search/ — Blocks internal search result pages (low-value for indexing)
  • Disallow: /?s= — Blocks search URLs with query parameters
  • Disallow: /wp-json/ — Blocks the REST API endpoint (optional, but reduces crawl waste)
  • Disallow: /wp-login.php — Blocks the login page

How to add robots.txt to WordPress

There are three main methods:

Method 1: SEO plugin

Plugins like Yoast SEO, Rank Math, and AIOSEO include a robots.txt editor. In Yoast, go to SEO → Tools → File Editor. In Rank Math, go to Rank Math → General Settings → Edit robots.txt.

Method 2: Theme file editor

Go to Appearance → Theme File Editor. Create a new file called robots.txt in your theme directory. This method is less reliable because the file may be removed when you update your theme.

Method 3: FTP or hosting control panel

Upload a physical robots.txt file to your site's root directory (the same directory as wp-config.php). This is the most reliable method because it persists through theme and plugin updates.

Common WordPress robots.txt mistakes

Blocking CSS and JavaScript

Some site owners block /wp-content/ to hide plugin and theme files. This prevents Googlebot from rendering your pages correctly, which can hurt rankings. Never block CSS, JavaScript, or image files.

Blocking admin-ajax.php

If you block the entire /wp-admin/ directory without allowing /wp-admin/admin-ajax.php, many themes will break. Forms, comments, and dynamic content may stop working.

Forgetting the sitemap

Always include a Sitemap directive pointing to your XML sitemap. This helps search engines discover your content efficiently.

Testing your WordPress robots.txt

After creating your robots.txt, test it using the NodSEO Robots.txt Generator or Google Search Console's robots.txt Tester. Verify that:

  • Important pages are accessible (not blocked)
  • Admin and low-value pages are blocked
  • The sitemap URL is correct
  • CSS, JavaScript, and images are allowed

Frequently Asked Questions

Does WordPress have a robots.txt file?

WordPress does not create a physical robots.txt file by default. However, WordPress will serve a virtual robots.txt if no physical file exists. This virtual file blocks /wp-admin/ and allows everything else.

Where do I edit robots.txt in WordPress?

You can edit robots.txt through your SEO plugin (Yoast, Rank Math, AIOSEO), through the Theme File Editor (Appearance → Theme File Editor), or by uploading a physical robots.txt file to your site's root directory via FTP.

What should I block in WordPress robots.txt?

Block /wp-admin/ (except admin-ajax.php), /search/, /?s= query parameters, /wp-json/, and /wp-login.php. Allow all CSS, JavaScript, images, and your sitemap.

Should I block /wp-admin/ in robots.txt?

Yes, but allow /wp-admin/admin-ajax.php. Many themes and plugins load content through admin-ajax.php, so blocking the entire directory can break functionality.

What is the best robots.txt for WordPress?

A good WordPress robots.txt blocks /wp-admin/ (except admin-ajax.php), /search/, and query parameter URLs while allowing all CSS, JS, and images. Include your sitemap URL.

Related Comparisons

Related Guides

Generate Your WordPress Robots.txt

Use the Robots.txt Generator with the WordPress preset to create a properly configured file.

Open Robots.txt Generator