The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →An October 2022 scan by sdcat found more than 45,000 publicly reachable PHP information pages across 2.6 million domains. A public phpinfo() page is not an exploit by itself, but it can give attackers a detailed map of a server—and may reveal credentials or keys that must be treated as compromised.
What is phpinfo()?
phpinfo() is a PHP function that displays information about the PHP installation and its environment. Developers and administrators sometimes use it to troubleshoot a server, confirm loaded extensions, or inspect configuration. A common temporary diagnostic file is named phpinfo.php or info.php, but the filename can vary.
The output can include the PHP version, build and compilation details, loaded modules, configuration values, web-server and operating-system details, environment variables, server variables, and information from HTTP requests. What appears depends on the PHP setup and the variables available to the application.
What did the 2022 scan find?
sdcat reported that its October 2022 scan covered 2.6 million domains and identified more than 45,000 accessible phpinfo pages. Those are historical scan figures, not a measurement of how common the exposure is today; they should not be treated as a current prevalence rate.
#1 Best Overall
The contemporaneous report described pages exposing PHP and web-server versions, OpenSSL and ImageMagick details, PHP settings, environment variables, and $_SERVER values. It also reported about 500 direct web-application IP addresses in $_SERVER that, according to the report, were intended to sit behind a web application firewall. That is a finding from the scan, not an estimate of how many sites overall have this configuration.
The article said ImageMagick versions could be identified on about one-third of the accessible pages it examined, and that 90% of the reported libraries were outdated. These are observations attributed to that scan report—not universal rates of vulnerable software. An old version number alone does not prove that a server is exploitable: maintenance and backports can differ by vendor and distribution.
Is an exposed phpinfo page dangerous?
It is an information-disclosure risk. Version numbers, enabled extensions, internal addresses, and configuration details help an attacker identify what is running and research possible weaknesses. That can make reconnaissance and follow-on attacks more targeted, but disclosure alone does not establish that a system has been breached or that a particular component is exploitable.
The more immediate concern is sensitive data in the output. sdcat’s report listed database passwords, email credentials, private keys, API secrets, live Stripe keys, cloud database credentials, message-queue credentials, and encryption keys among the exposed values. A phpinfo page does not create those secrets; it can reveal them when applications or servers place them in environment or server variables that the page prints.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesRank #3
If a secret appeared on a page anyone could access, treat it as compromised even if you have no evidence that someone used it. Removing the page prevents further disclosure, but it does not undo any access that may already have occurred.
How to remove or restrict a phpinfo page
- Find every diagnostic endpoint. Check production document roots, application routes, deployment artifacts, and repositories for
phpinfo()and common filenames such asphpinfo.phpandinfo.php. Search all production hosts and domains, not just the main site. - Delete it from production. Remove the file or route, then request its exact URL from an unauthenticated browser or command-line client. Confirm it no longer returns phpinfo output; a 404 or an access-denied response is preferable to the diagnostic page.
- Keep temporary diagnostics behind controls. If operational work requires a phpinfo page, do not leave it publicly reachable. Require strong authentication and restrict access to trusted administrative networks or an equivalent access policy. Remove it when the task is complete.
- Rotate exposed secrets. Revoke and replace every password, token, key, or credential shown in a previously public output. Update dependent applications and services, and review relevant access logs for suspicious use.
- Review affected components and configuration. Check PHP, the web server, OpenSSL, ImageMagick, and application dependencies against the support channels and security advisories for the specific vendor or distribution. Review settings such as
display_errors, environment handling, server headers, and URL-include behavior in context; no single setting substitutes for removing the endpoint. - Verify the fix across your estate. Repeat the check across all owned domains and hosts, including unauthenticated access from outside the network. An authorized security scanner can help find forgotten endpoints at scale; confirm that its checks are current and run only against systems you own or are authorized to test.
Can expose_php prevent phpinfo exposure?
No. PHP’s manual says, “By setting expose_php to off in your php.ini file, you reduce the amount of information available to them.” This can reduce PHP fingerprinting through ordinary responses, but it does not remove or protect a publicly accessible phpinfo endpoint. Delete the page or put it behind access controls.
Rank #4
How to check your site for phpinfo exposure
For a small site, test the known diagnostic URLs directly and search the application and deployment files for phpinfo(). For a larger portfolio, use an authorized web-security scanner with coverage for every owned host. Check from both an unauthenticated public perspective and, where appropriate, an authenticated administrative perspective; a page protected internally may still be open externally if access controls are misconfigured.
Do not rely only on familiar filenames: a diagnostic page can use any name or be served by an application route. After removing a finding, repeat the scan and confirm the response no longer contains PHP configuration output. Keep the scan scoped to assets you control or have permission to test.
Recommended Free Tools
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

