Control other sites linking directly to your files
Configure Hotlink Protection without breaking your own images or trusted integrations.
Where Tools → Security → Hotlink Protection
Before you start
- List every legitimate site origin that embeds the protected files, including www, HTTPS and any approved CDN.
- Back up existing settings before enabling protection.
Steps
-
1
Open Hotlink Protection and read whether it is enabled or disabled.
-
2
Review URLs to allow access. Include the legitimate origins that must embed your files.
-
3
Set the extensions to protect as a comma-separated list. Protecting image types is different from blocking all links to the website.
-
4
Submit the configuration, then use Enable if protection is still disabled. Do not assume saving a list and enabling the feature are the same action.
-
5
Choose whether to Allow direct requests, such as someone opening an image URL directly. Set an optional redirect only when you have a suitable destination.
Review allowed origins, extensions and direct-request behaviour.
Check it worked
- Load images on your own site, including www/non-www variants and approved integrations.
- Check direct-file access behaves as intended. Restore the previous settings if legitimate assets fail.