Patchstack Auto-Prepend Firewall: What It Does and How to Fix the auto_prepend_file Conflict

Updated October 9, 2026 · 4 min read

Site Security PRO, powered by Patchstack, has two firewall settings under WordPress → Vulnerability Scan → Protection → Additional settings:

  • Enable firewall is the standard Patchstack firewall. It runs inside WordPress and should stay on.
  • Enable auto-prepend firewall (Beta) is optional. It loads the Patchstack firewall before WordPress, so it also inspects requests that never reach WordPress.

This guide explains what the second one does, why you might see the error “Auto-prepend firewall error occurred: A different auto_prepend_file value is already present in the .htaccess file”, and how to clear it without touching your protection.

What the auto-prepend firewall does

PHP has a setting called auto_prepend_file that runs one file before any other PHP script. Patchstack uses it to load its firewall first on every request, including direct hits to plugin or theme files that bypass WordPress. When you turn the toggle on, Patchstack writes a php_value auto_prepend_file … directive into the site’s .htaccess, which OpenLiteSpeed (and Apache) honour.

With Enable firewall on, your site is already protected against the exploit patterns Patchstack knows about. Auto-prepend is an extra layer, not a requirement. Leaving it off is a perfectly fine choice.

Why the error appears

Only one auto_prepend_file directive can be active. Patchstack checks .htaccess before writing its own, and if it finds a directive that points somewhere else, it refuses to overwrite it and shows the error instead.

In almost every case the existing line is a leftover from a previous security plugin. Wordfence, NinjaFirewall and similar plugins use the same mechanism for their own firewalls, and removing the plugin does not always remove the directive. It is not a conflict between server settings and site settings, and resetting the Patchstack connection does not clear it.

Fix it in six steps

You need the site’s File Manager (or SFTP). The steps are the same on every site that shows the error.

  1. Open the site in xCloud and go to File Manager. Open .htaccess in the site root. Make a copy of the file first.
  2. Search for auto_prepend_file. You will find a line, often inside an <IfModule> block, that references a file such as wordfence-waf.php or a NinjaFirewall file.
  3. If that plugin is no longer installed, or you no longer use its firewall, delete the line. If the <IfModule> block around it is now empty, delete the block too. If the plugin is still active and you want to keep its firewall, stop here: two firewalls cannot share this directive, so choose one.
  4. Check for a .user.ini file in the site root. If it contains an auto_prepend_file line pointing to the same old plugin, remove that line as well.
  5. Back in xCloud, open WordPress → Vulnerability Scan → Protection → Additional settings. Turn Enable auto-prepend firewall off, click Save settings, turn it on, and click Save settings again. Patchstack writes its own directive this time.
  6. Purge the site cache from the Caching page and load the site once to confirm it works.

Protection stays active throughout; there is no need to disable Site Security PRO or wait for the feature to leave Beta.

  • Site Security PRO is available for WordPress sites only. Custom PHP, Node and Docker sites do not appear in the subscription dropdown.
  • If the Additional settings tab itself fails to load with “Failed to connect site”, that is a different problem: see How To Solve Site Security PRO Failing to Connect.
  • If a security plugin’s firewall directive points at a file that no longer exists, PHP fails on every request and the site returns a 500. The same .htaccess / .user.ini cleanup fixes it.

If you run into any issues with Site Security PRO, feel free to reach out to our support team.

Frequently asked questions

Is my site unprotected while the auto-prepend firewall shows this error?

No. The standard Patchstack firewall, enabled with the Enable firewall toggle, is already protecting the site. Auto-prepend only widens the coverage to requests that never reach WordPress.

Do I have to disable Site Security PRO before editing .htaccess?

No. Edit the file, remove the stale line, then toggle the auto-prepend setting off and on so Patchstack writes its own directive. Protection stays active throughout.

Can I just leave auto-prepend off?

Yes. It is optional and marked Beta. The standard firewall, virtual patching and vulnerability monitoring all work without it.