Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Disable PHP Functions in WHM

You can stop risky PHP functions from running on your server. This guide shows how, using WHM. It needs root access.

WHM2 min read12 steps4 screenshots

What is a PHP function?

PHP is a language many websites use. A function is a small ready-made job, like "send an email" or "run a command". Some functions are dangerous. If a hacker gets into a site, they could use a function such as exec to run commands on your server. Turning these off is like locking the tool cupboard.

Warning: Some websites need these functions. If you disable one, a site may stop working. Take a backup of the PHP configuration first, and test your sites afterwards.

Steps

  1. Log in to WHM as root.
    Screenshot: Log in to WHM as root .
  2. In the search box, type MultiPHP INI Editor and open it.
    Screenshot: In the search box, type MultiPHP INI Editor and open it.
  3. Choose the Editor Mode tab. This shows the raw text of the PHP settings file, called php.ini.
  4. Pick the PHP version you want to change from the list.
  5. Look for the line that starts with disable_functions.
  6. Add the functions you want to block. Separate each name with a comma, with no spaces. For example:
disable_functions = exec,passthru,shell_exec,system,proc_open,popen

This line tells PHP to refuse to run those six functions.

Screenshot: This line tells PHP to refuse to run those six functions.
  1. Click Save.
  2. Repeat for other PHP versions if your server has more than one.

If you do not see an Editor Mode tab, use the Basic Mode tab instead. It has a box called disable_functions where you can type the names.

Check that it worked

  1. Make a file called info.php in a test site with this one line:
<?php phpinfo(); ?>

This line shows a page full of PHP settings.

  1. Open the file in your browser and search for disable_functions.
  2. Your list should appear there.
  3. Delete info.php afterwards. Anyone can read it.
    Screenshot: Delete info.php afterwards. Anyone can read it.
Tip: If a site breaks, remove one function from the list at a time until it works again.

Quick recap

  • Disabling risky PHP functions makes hacked sites less harmful.
  • Use MultiPHP INI Editor in WHM and edit disable_functions.
  • Separate names with commas.
  • Test your sites afterwards because some need these functions.