What is Magic Quotes?
PHP is a language that runs on web servers. Years ago, PHP had a feature called Magic Quotes. GPC stands for GET, POST and Cookie. These are the ways data reaches a script from a web form or address. With Magic Quotes on, PHP added a backslash before quote marks in that data. So O'Brien became O\'Brien. The idea was to protect databases from bad input. It did not work well. It caused messy text and gave a false sense of safety.
Magic Quotes was removed in PHP 5.4. On PHP 5.4 and newer, the setting does not exist. You only need this guide if you run very old PHP (5.3 or lower). That is old and unsafe. Newer versions work in a better way, so upgrade if you can.
Check your PHP version first
- Log in to your hosting control panel.
- Open a tool such as Select PHP Version or MultiPHP Manager, if you have one.
- Read the version number. If it is 5.4 or higher, you do not need to do anything.
Turn it off in php.ini
- Open File Manager in your control panel.
- Go to your website folder, often
public_html. - Open or create a file named
php.ini. - Add this line.
magic_quotes_gpc = Off - Click Save Changes.
Turn it off in .htaccess
This works only if PHP runs as an Apache module. Open .htaccess in the same folder and add:
php_flag magic_quotes_gpc Off
If your site shows a 500 error after this, remove the line. Your server does not allow it.
Turn it on
You normally should not. Use magic_quotes_gpc = On only for an ancient script that needs it. A better fix is to update that script and use prepared statements. These are the safe way to send data to a database.
Check the result
- Create a file with
<?php phpinfo();. - Open it in your browser and search for
magic_quotes_gpc. - Delete the file afterwards.
Quick recap
- Magic Quotes added backslashes to incoming data.
- It was removed in PHP 5.4.
- On old PHP, set
magic_quotes_gpc = Offinphp.ini. - Upgrade PHP and use prepared statements instead.