How to change the PHP version and settings in cPanel

Change PHP version per domain with MultiPHP Manager, raise limits such as memory_limit and upload_max_filesize with the INI Editor, and understand CloudLinux’s PHP Selector.

2–3 minutes

Sites need a supported PHP version, and sometimes more memory or larger uploads than the defaults allow. cPanelcPanel The most popular hosting control panel: a website where you manage your email, files, databases and domains with point-and-click tools instead of commands. More about cPanel → has two tools for this, and CloudLinux servers add a third. Which one to use depends on how your host set the server up.

Use Software » MultiPHP Manager to choose the PHP version for each domain, and Software » MultiPHP INI Editor to change settings such as memory_limit and upload_max_filesize. If your host uses CloudLinux, Select PHP Version may be the tool that controls PHP instead.

Which tool controls PHP?

ToolWhereControls
MultiPHP ManagerSoftwarePHP version per domain (the ea-php versions)
MultiPHP INI EditorSoftwarePHP settings per domain or folder
Select PHP VersionSoftware, on CloudLinux serversVersion, extensions and settings (the alt-php versions)

On CloudLinux servers, sites using a version from MultiPHP Manager ignore Select PHP Version, and the other way round. If a change seems to do nothing, you are probably in the other tool.

Change the PHP version

cPanel MultiPHP Manager with the domain checkbox, PHP version menu and Apply button highlighted
Software » MultiPHP Manager. The warning lists versions that no longer receive security fixes.
  1. Tick the domain or domains to change.
  2. Choose the PHP Version.
  3. Click Apply.

The change is immediate. Then load your site and its admin area. If something breaks, switch back the same way.

Choose the newest version your software supports. Versions marked deprecated no longer receive security fixes and should only be used while you upgrade old code. For WordPress, check plugins and themes are up to date first; old plugins are the usual reason a site fails on a newer PHP.

Change PHP settings

cPanel MultiPHP INI Editor basic mode showing directives such as max_execution_time, memory_limit, post_max_size and upload_max_filesize
Software » MultiPHP INI Editor, Basic Mode. Pick the location first.
  1. Choose the location: Home Directory for all sites, or a specific domain.
  2. Change the values you need.
  3. Scroll down and click Apply.

The settings people change most:

DirectiveDefault hereRaise it when
memory_limit128M“Allowed memory size exhausted” errors; try 256M
upload_max_filesize2MUploads of large images, themes or plugins fail
post_max_size8MMust be at least as large as upload_max_filesize
max_execution_time30Imports or reports time out; try 120
max_input_vars1000Large menus or forms lose settings when saved

Raise values only as far as you need. A very high memory_limit hides a badly written plugin instead of fixing it, and on shared hostingShared hosting Hosting where your website shares one server with many others. Cheap and simple; the host looks after the server. More about Shared hosting → your account’s own memory limit still applies.

Editor Mode shows the raw php.ini text for the chosen location, for settings the basic list does not include.

CloudLinux: Select PHP Version

CloudLinux PHP Selector showing the PHP version set to native and a notice that modules cannot be changed for the native version
Software » Select PHP Version on a CloudLinux server.

On CloudLinux servers, the PHP Selector offers its own versions and lets you switch individual extensions on and off, such as imagick, intl or redis. While the version is native, PHP follows MultiPHP Manager and the extension list is locked, as the notice here says. Choose a specific version to unlock extensions and an Options tab with settings like those above.

Check what is actually running

Create a file named info.php in the site’s folder containing:

<?php phpinfo();

Open https://example.com/info.php, check the version and the settings you changed, then delete the file: it reveals details about the server that attackers can use.

Something out of date? Software changes. If a step no longer works, tell us and we will check it and update the page.