2 min read Sep 26, 2026

Which PHP Functions Are Disabled on WordPress Hosting?

For security, FimuroHost's WordPress-optimised hosting disables a small set of PHP functions such as exec and shell_exec. See the full list and what to do if a plugin needs one.

FimuroHost Team

FimuroHost Team

Technical Writer

Share Article

FimuroHost's WordPress-optimised packages use tuned firewall rules and several extra layers of protection to keep WordPress sites safe.

One of those layers is switching off a handful of PHP functions that attackers often abuse to run commands on a server once they've found a weak plugin.

The disabled functions

  • exec
  • opcache_get_configuration
  • opcache_get_status
  • passthru
  • parse_ini_file
  • popen
  • proc_open
  • shell_exec
  • show_source
  • system

Will this affect my site?

Almost certainly not. Well-written WordPress plugins and themes don't rely on these functions, because many hosts block them.

If one does, you'll usually see an error like Call to undefined function exec() in your error log. Since PHP 8, disabled functions behave as if they don't exist.

If you really need one of them

  • Look for an alternative plugin that does the same job without shell access. This is usually the quickest fix.
  • Move to standard Cloud Hosting: you can host WordPress on a standard Linux Cloud Hosting package, where these WordPress-specific restrictions don't apply. Contact support and we'll help you choose and move the site.

Tip

Only install plugins from trusted sources and keep them updated. Disabled functions reduce the damage a vulnerable plugin can do, but they don't replace good updates.

Need help?

If something doesn't work as described, open a support ticket from your client area or message us on WhatsApp at 01818160926. Tell us the domain name and what you have already tried, and we'll take it from there.

FimuroHost Team

Written by

FimuroHost Team

Technical Writer