A public phpinfo() page gives away your server’s secrets.
phpinfo() is PHP’s built-in diagnostics page. People create phpinfo.php or info.php to check a new setup, and forget to delete it. Anyone who loads it sees exactly how the server is built — and often its secrets.
What it reveals
- Environment and server variables. The “Environment” and “PHP Variables” tables list every variable PHP was given, so secrets passed that way — Apache
SetEnv, nginxfastcgi_param, PHP-FPMenv[…],docker run -e— are printed in full. - The visitor’s own request, cookies included. phpinfo echoes request headers, including cookies marked HttpOnly. Together with a cross-site scripting bug, that lets an attacker read session cookies that JavaScript normally can’t.
- A map of the server. The exact PHP version and build, loaded extensions, the document root and file paths,
disable_functionsandopen_basedir— what an attacker needs to pick an exploit that fits.
1. Find and delete it
DotenvScan checks the two usual names. Copies often live under others, so search for the call itself:
find /var/www -type f -name '*.php' -exec grep -lE 'phpinfo[[:space:]]*\(' {} +
Delete the test pages it lists. If application code calls phpinfo() on purpose (some admin panels do), make sure it sits behind a login. When you need the information yourself, php -i on the command line shows it without a web page — for the CLI’s configuration, which can differ from the web server’s.
2. Disable phpinfo() as a safety net
In the php.ini your web server uses, add phpinfo to disable_functions (keep anything already listed), then reload PHP:
disable_functions = phpinfo
sudo systemctl reload php8.3-fpm # or apache2, for mod_php
A forgotten test page then shows nothing. disable_functions can only be set in php.ini, not per site in .htaccess.
3. Rotate what it showed
Before deleting the page, note every secret in its “Environment” and “PHP Variables” tables — or check your server and PHP-FPM configuration for the variables you pass in — and rotate each one, as in the exposed .env guide.
4. Check whether it was found
sudo zgrep -hE '"GET /([^ "]*/)?(phpinfo|info)\.php[^ "]* HTTP/[0-9.]+" 200 ' /var/log/nginx/access.log*
For Apache, search /var/log/apache2/access.log* or /var/log/httpd/access_log*. Any hit you didn’t make means the page was read.