Explainer

phpinfo(): what it shows, and how to check PHP settings safely.

phpinfo() is a built-in PHP function that prints a full report of how PHP is set up: its version, every setting, every loaded extension, and the variables of the current request. A phpinfo.php page is a one-line file that calls it. It is handy while setting up a server, and a gift to attackers if it is left online.

How to make a phpinfo page

<?php phpinfo();

Save that as a .php file in the web root and open it in a browser. To do it safely:

<?php phpinfo(INFO_GENERAL | INFO_CONFIGURATION | INFO_MODULES);

What each section shows

SectionFlagWhat’s in it
GeneralINFO_GENERALPHP version, operating system and host name, build options, Server API (FPM, Apache module, CLI), and which php.ini files were loaded.
ConfigurationINFO_CONFIGURATIONEvery PHP directive, with its local and master value: memory_limit, upload_max_filesize, disable_functions, open_basedir, session settings.
ModulesINFO_MODULESEach loaded extension with its version and settings: mysqli, curl, openssl, gd and so on.
EnvironmentINFO_ENVIRONMENTThe environment variables PHP was started with — including any secrets passed that way.
PHP VariablesINFO_VARIABLES$_SERVER, $_COOKIE, $_GET, $_POST and $_ENV: the request headers, the visitor’s cookies, and values the web server passes to PHP.
Credits, LicenseINFO_CREDITS, INFO_LICENSEThe PHP authors and licence text.

INFO_ALL, the default, prints everything. On the command line, phpinfo() prints the same report as plain text.

Check PHP settings without a web page

On the server, the command line answers most questions phpinfo() is used for:

php -v                           # version
php --ini                        # which php.ini files are loaded
php -m                           # loaded extensions
php -i | grep -i memory_limit    # one setting
php-fpm -i | grep -i memory_limit   # the same, for PHP-FPM

The command-line PHP and the PHP behind your web server can load different php.ini files (on Debian and Ubuntu, /etc/php/8.3/cli/ and /etc/php/8.3/fpm/), so php -i may not show what your site sees. php-fpm -i reports the FPM configuration; the binary is called php-fpm8.3 or similar on Debian and Ubuntu.

From inside code, single values are one call each: phpversion(), ini_get('memory_limit'), extension_loaded('gd'), php_ini_loaded_file(). On WordPress, Tools → Site Health → Info → Server shows the PHP version and limits with no extra file at all.

Is phpinfo() a security risk?

The function isn’t; a public page that calls it is. It is information disclosure, and security scanners report it as such:

If one is online now, the phpinfo exposed guide covers finding every copy, disabling the function in php.ini, rotating what it showed and checking your logs.

Check your site

DotenvScan requests /phpinfo.php and /info.php in every scan and tells you if either prints a phpinfo report, alongside .env, wp-config.php and .git.

Scan for phpinfo pages