# Patchstack Auto-Prepend Firewall: What It Does and How to Fix the auto_prepend_file Conflict

> Site Security PRO's optional auto-prepend firewall loads Patchstack before WordPress. If it reports that a different auto_prepend_file value is already present, a previous security plugin left a directive behind. Here's the safe fix.

[Site Security PRO](/docs/set-up-site-security-pro/), powered by Patchstack, has two firewall settings under **WordPress → Vulnerability Scan → Protection → Additional settings**:

- **Enable firewall** is the standard Patchstack firewall. It runs inside WordPress and should stay on.
- **Enable auto-prepend firewall** (Beta) is optional. It loads the Patchstack firewall before WordPress, so it also inspects requests that never reach WordPress.

This guide explains what the second one does, why you might see the error **"Auto-prepend firewall error occurred: A different auto_prepend_file value is already present in the .htaccess file"**, and how to clear it without touching your protection.

## What the auto-prepend firewall does

PHP has a setting called `auto_prepend_file` that runs one file before any other PHP script. Patchstack uses it to load its firewall first on every request, including direct hits to plugin or theme files that bypass WordPress. When you turn the toggle on, Patchstack writes a `php_value auto_prepend_file …` directive into the site's `.htaccess`, which OpenLiteSpeed (and Apache) honour.

With **Enable firewall** on, your site is already protected against the exploit patterns Patchstack knows about. Auto-prepend is an extra layer, not a requirement. Leaving it off is a perfectly fine choice.

## Why the error appears

Only one `auto_prepend_file` directive can be active. Patchstack checks `.htaccess` before writing its own, and if it finds a directive that points somewhere else, it refuses to overwrite it and shows the error instead.

In almost every case the existing line is a leftover from a **previous security plugin**. Wordfence, NinjaFirewall and similar plugins use the same mechanism for their own firewalls, and removing the plugin does not always remove the directive. It is not a conflict between server settings and site settings, and resetting the Patchstack connection does not clear it.

## Fix it in six steps

You need the site's **File Manager** (or SFTP). The steps are the same on every site that shows the error.

1. Open the site in xCloud and go to **File Manager**. Open `.htaccess` in the site root. Make a copy of the file first.
2. Search for `auto_prepend_file`. You will find a line, often inside an `<IfModule>` block, that references a file such as `wordfence-waf.php` or a NinjaFirewall file.
3. If that plugin is **no longer installed**, or you no longer use its firewall, delete the line. If the `<IfModule>` block around it is now empty, delete the block too. If the plugin is still active and you want to keep its firewall, stop here: two firewalls cannot share this directive, so choose one.
4. Check for a `.user.ini` file in the site root. If it contains an `auto_prepend_file` line pointing to the same old plugin, remove that line as well.
5. Back in xCloud, open **WordPress → Vulnerability Scan → Protection → Additional settings**. Turn **Enable auto-prepend firewall** off, click **Save settings**, turn it on, and click **Save settings** again. Patchstack writes its own directive this time.
6. Purge the site cache from the **Caching** page and load the site once to confirm it works.

Protection stays active throughout; there is no need to disable Site Security PRO or wait for the feature to leave Beta.

## Related

- Site Security PRO is available for WordPress sites only. Custom PHP, Node and Docker sites do not appear in the subscription dropdown.
- If the **Additional settings** tab itself fails to load with "Failed to connect site", that is a different problem: see [How To Solve Site Security PRO Failing to Connect](/docs/site-security-pro-powered-by-patchstack-failing-to-connect-error/).
- If a security plugin's firewall directive points at a file that no longer exists, PHP fails on every request and the site returns a 500. The same `.htaccess` / `.user.ini` cleanup fixes it.

If you run into any issues with Site Security PRO, feel free to reach out to our [support team](/docs/access-built-in-support-portal-in-xcloud/).

## Frequently asked questions

### Is my site unprotected while the auto-prepend firewall shows this error?

No. The standard Patchstack firewall, enabled with the Enable firewall toggle, is already protecting the site. Auto-prepend only widens the coverage to requests that never reach WordPress.

### Do I have to disable Site Security PRO before editing .htaccess?

No. Edit the file, remove the stale line, then toggle the auto-prepend setting off and on so Patchstack writes its own directive. Protection stays active throughout.

### Can I just leave auto-prepend off?

Yes. It is optional and marked Beta. The standard firewall, virtual patching and vulnerability monitoring all work without it.
