---
title: "Secure php.ini Settings: A Practical Guide for cPanel and CloudLinux"
description: "**In short:** php.ini controls PHP security and limits. On our hosting you change it from cPanel, then Select PHP Version, then Options, without editing any file. Recommended secure settings: expose_php = Off, allow_url_include = Off and display_errors = Off on…"
url: "https://www.hyyat.com/en/knowledgebase/secure-php-ini-settings/"
updated: "2026-09-29"
category: Server management / servers without control panel
---

# Secure php.ini Settings: A Practical Guide for cPanel and CloudLinux

**In short:** php.ini controls PHP security and limits. On our hosting you change it from cPanel, then Select PHP Version, then Options, without editing any file. Recommended secure settings: expose_php = Off, allow_url_include = Off and display_errors = Off on a live site, with memory_limit, upload_max_filesize and post_max_size set to what your site needs. safe_mode, register_globals and magic_quotes_gpc were removed from PHP years ago and do not exist in current versions.

**php.ini** is the PHP configuration file. It controls things like the memory limit, the maximum upload size, error display and some security options. Setting it correctly protects your site and prevents many errors.

## 1. Change PHP settings on shared hosting

On Hyyat Host hosting you do not need to edit php.ini by hand. Our servers run CloudLinux, and you change the settings from cPanel:

1. Log in to cPanel.
2. In the **Software** section, click **Select PHP Version**.
3. Open the **Options** tab and change the value you need. It is saved automatically.

From the **Extensions** tab on the same page you can enable extensions your site needs, such as ioncube_loader or imagick.

## 2. Recommended secure settings

- **expose_php = Off**: hides your PHP version from server responses.
- **allow_url_include = Off**: blocks including PHP files from remote URLs. Always keep it off; it is a common attack path.
- **allow_url_fopen**: lets PHP read files from URLs. Many plugins and scripts need it (such as WordPress updates and payment gateways), so only turn it off if you are sure your site does not use it.
- **display_errors = Off**: do not show errors to visitors on a live site, because they can reveal paths and internal details. Use the error log instead.
- **memory_limit**: the maximum memory per PHP process. 256M is enough for most WordPress sites.
- **upload_max_filesize and post_max_size**: the maximum upload size. Keep post_max_size equal to or larger than upload_max_filesize.
- **max_execution_time**: the maximum run time of a script in seconds. Raise it only temporarily, for example when importing large files.

**Old settings that no longer exist:** safe_mode, register_globals and magic_quotes_gpc were removed from PHP (in versions 5.4 and 7). Any guide that asks you to change them is outdated.

## 3. On a VPS or dedicated server

If you have a server with WHM, change the settings from **WHM, then Software, then MultiPHP INI Editor**, or from CloudLinux PHP Selector if it is installed. To find the php.ini file in use, connect over SSH (see [how to connect to your server over SSH](https://www.hyyat.com/en/knowledgebase/how-to-connect-to-a-server-via-ssh/)) and run:

```
php --ini
```

**disable_functions**: on your own server you can disable risky functions such as exec, shell_exec, system, passthru, proc_open and popen. Do it carefully and test your sites afterwards, because some plugins and backup tools need them. Do not copy long lists from the internet; they can break your sites.

After editing php.ini, restart PHP or Apache so the change takes effect.

**Related service:** [Hyyat Host server management](https://www.hyyat.com/en/server-management/) can tune PHP and security settings on your server, with 24/7 support.

 **Need this service from Hyyat Host?**Our team handles it for you, with support replying to tickets within 24 hours at most.[Server Management](https://www.hyyat.com/en/server-management/)[dedicated server](https://www.hyyat.com/en/dedicated-server/)
