When a security test or fix asks you to change functions.php, edit the child theme file, not the parent theme.
Why the child theme
- Parent theme updates overwrite
functions.phpchanges. - Declaring the same function in both parent and child theme can cause a fatal “function already exists” error, because WordPress loads both.
If you do not have a child theme yet, create one before you add custom code.
Steps
- Connect via FTP, SFTP, or your host file manager (FTP guide).
- Open
wp-content/themes/and find your child theme folder. - Edit
functions.phpin that folder. - Add only the snippet the docs or plugin instruct you to add.
- Save, then reload the site and re-run the relevant security test.
Prefer a child theme or a small custom plugin for permanent snippets. Avoid editing parent theme files on a live site without a backup.