Free tool · runs in your browser
🛡️ php.ini Security & Performance Checker
Paste your php.ini or the output of php -i to get a graded report of risky and slow settings, with the exact lines to fix. It runs in your browser: nothing is uploaded.
Runs in your browser: what you enter is never sent anywhere. We only count anonymous usage, such as which buttons are used, to improve the tools.
What the checker looks at
It grades 22 production settings in three groups. Security covers error display, remote file inclusion, shell functions and version disclosure. Sessions covers the cookie flags that stop session theft and fixation. Performance covers OPcache, memory and execution limits.
Each problem is weighted by severity: a critical issue such as display_errors = On in production costs far more than an informational one such as leaving allow_url_fopen enabled. The grade reflects that weighting, so an A means no meaningful risk remains.
Applying the fixes safely
- Find the php.ini your web server actually loads:
php --inifor the CLI, orphpinfo()for PHP-FPM, which often uses a different file. - Change one group at a time and reload PHP-FPM (
systemctl reload php8.3-fpm, adjusted to your version). - Before disabling functions, search your code and dependencies for them; some libraries need
proc_open. - If you turn off
opcache.validate_timestamps, reset OPcache as part of every deploy, or new code won’t be picked up.
Frequently asked questions
Is my php.ini uploaded anywhere?
No. The checker runs entirely in your browser with JavaScript. Nothing you paste is sent to a server, logged or stored.
Which php.ini settings matter most for security?
Turn off display_errors and allow_url_include, disable shell functions you don’t use with disable_functions, and harden session cookies with session.cookie_httponly, session.cookie_secure, session.cookie_samesite and session.use_strict_mode.
What are good OPcache settings for production?
Keep opcache.enable on, give it 128–256 MB with opcache.memory_consumption, raise opcache.interned_strings_buffer to 16 and opcache.max_accelerated_files to at least 20000, and set opcache.validate_timestamps to 0 while resetting OPcache on every deploy.
How do I get my current settings?
Paste your php.ini file, or run php -i (or php -i > settings.txt) on the server and paste the output. For PHP-FPM, check the php.ini the FPM pool loads, since the CLI can use a different file.