php.ini is the PHP configuration file. It controls things like the memory limit, the maximum upload size, error display and some security options. Setting it correctly protects your site and prevents many errors.
1. Change PHP settings on shared hosting #
On Hyyat Host hosting you do not need to edit php.ini by hand. Our servers run CloudLinux, and you change the settings from cPanel:
- Log in to cPanel.
- In the Software section, click Select PHP Version.
- Open the Options tab and change the value you need. It is saved automatically.
From the Extensions tab on the same page you can enable extensions your site needs, such as ioncube_loader or imagick.
2. Recommended secure settings #
- expose_php = Off: hides your PHP version from server responses.
- allow_url_include = Off: blocks including PHP files from remote URLs. Always keep it off; it is a common attack path.
- allow_url_fopen: lets PHP read files from URLs. Many plugins and scripts need it (such as WordPress updates and payment gateways), so only turn it off if you are sure your site does not use it.
- display_errors = Off: do not show errors to visitors on a live site, because they can reveal paths and internal details. Use the error log instead.
- memory_limit: the maximum memory per PHP process. 256M is enough for most WordPress sites.
- upload_max_filesize and post_max_size: the maximum upload size. Keep post_max_size equal to or larger than upload_max_filesize.
- max_execution_time: the maximum run time of a script in seconds. Raise it only temporarily, for example when importing large files.
Old settings that no longer exist: safe_mode, register_globals and magic_quotes_gpc were removed from PHP (in versions 5.4 and 7). Any guide that asks you to change them is outdated.
3. On a VPS or dedicated server #
If you have a server with WHM, change the settings from WHM, then Software, then MultiPHP INI Editor, or from CloudLinux PHP Selector if it is installed. To find the php.ini file in use, connect over SSH (see how to connect to your server over SSH) and run:
php --ini
disable_functions: on your own server you can disable risky functions such as exec, shell_exec, system, passthru, proc_open and popen. Do it carefully and test your sites afterwards, because some plugins and backup tools need them. Do not copy long lists from the internet; they can break your sites.
After editing php.ini, restart PHP or Apache so the change takes effect.
Related service: Hyyat Host server management can tune PHP and security settings on your server, with 24/7 support.