phpinfo(): what it shows, and how to check PHP settings safely.
phpinfo() is a built-in PHP function that prints a full report of how PHP is set up: its version, every setting, every loaded extension, and the variables of the current request. A phpinfo.php page is a one-line file that calls it. It is handy while setting up a server, and a gift to attackers if it is left online.
How to make a phpinfo page
<?php phpinfo();
Save that as a .php file in the web root and open it in a browser. To do it safely:
- Give it a name nobody will guess, not
phpinfo.phporinfo.php: bots request those two names on site after site. - Show only what you need. The sections that carry secrets are “Environment” and “PHP Variables”; leave them out:
<?php phpinfo(INFO_GENERAL | INFO_CONFIGURATION | INFO_MODULES);
- Delete it as soon as you have read it. Most public phpinfo pages are test files from a setup months ago.
What each section shows
| Section | Flag | What’s in it |
|---|---|---|
| General | INFO_GENERAL | PHP version, operating system and host name, build options, Server API (FPM, Apache module, CLI), and which php.ini files were loaded. |
| Configuration | INFO_CONFIGURATION | Every PHP directive, with its local and master value: memory_limit, upload_max_filesize, disable_functions, open_basedir, session settings. |
| Modules | INFO_MODULES | Each loaded extension with its version and settings: mysqli, curl, openssl, gd and so on. |
| Environment | INFO_ENVIRONMENT | The environment variables PHP was started with — including any secrets passed that way. |
| PHP Variables | INFO_VARIABLES | $_SERVER, $_COOKIE, $_GET, $_POST and $_ENV: the request headers, the visitor’s cookies, and values the web server passes to PHP. |
| Credits, License | INFO_CREDITS, INFO_LICENSE | The PHP authors and licence text. |
INFO_ALL, the default, prints everything. On the command line, phpinfo() prints the same report as plain text.
Check PHP settings without a web page
On the server, the command line answers most questions phpinfo() is used for:
php -v # version
php --ini # which php.ini files are loaded
php -m # loaded extensions
php -i | grep -i memory_limit # one setting
php-fpm -i | grep -i memory_limit # the same, for PHP-FPM
The command-line PHP and the PHP behind your web server can load different php.ini files (on Debian and Ubuntu, /etc/php/8.3/cli/ and /etc/php/8.3/fpm/), so php -i may not show what your site sees. php-fpm -i reports the FPM configuration; the binary is called php-fpm8.3 or similar on Debian and Ubuntu.
From inside code, single values are one call each: phpversion(), ini_get('memory_limit'), extension_loaded('gd'), php_ini_loaded_file(). On WordPress, Tools → Site Health → Info → Server shows the PHP version and limits with no extra file at all.
Is phpinfo() a security risk?
The function isn’t; a public page that calls it is. It is information disclosure, and security scanners report it as such:
- Secrets. Database passwords and API keys passed as environment variables — PHP-FPM
env[…], nginxfastcgi_param, ApacheSetEnv,docker run -e— are printed in full. - Cookies. The page echoes the visitor’s cookies, including HttpOnly ones that JavaScript normally can’t read — useful to an attacker who has found a cross-site scripting bug.
- A map for an exploit. The exact PHP version, extensions, paths and which dangerous functions are still enabled.
If one is online now, the phpinfo exposed guide covers finding every copy, disabling the function in php.ini, rotating what it showed and checking your logs.
Check your site
DotenvScan requests /phpinfo.php and /info.php in every scan and tells you if either prints a phpinfo report, alongside .env, wp-config.php and .git.