PHP warnings showing on your site: what they are and how to silence them

At the top of the page, or in the middle of the dashboard, lines appear like Warning: ... in /home/account/public_html/wp-content/plugins/... on line 214. The site still works. But it is showing everybody the server folder paths, the account name and, sometimes, fragments of database queries.

This is a security problem before it is a cosmetic one. Automated scanners collect exactly this: full paths, versions and plugin names. Deal with it today, even if the site is working.

What the warnings are, and what they are not

Not every message carries the same weight. The word before the colon tells you everything:

The word What it means
Fatal error The page stopped here. It is the only one that actually breaks the site: common WordPress errors. If it mentions exhausted memory, giving WordPress more memory.
Warning Something went wrong but PHP carried on. A file that is not there, a connection that failed. It does not stop the page, but something is not happening.
Notice A slip in the code, like using a variable that was never set. Noise, until there are many of them.
Deprecated Code written for an old PHP version running on a new one. It is the warning that appears in the hundreds after moving to PHP 8.

First: silence them, in three places

The messages are on show because something told them to be. Usually one of these three, and it is worth checking all three in order:

1 In wp-config.php. Look for the WP_DEBUG line. If it is true, this is almost certainly it: somebody turned it on to diagnose something and never turned it off. Set define( 'WP_DEBUG', false );.
2 If you need diagnostics on, then send them to a file instead of the screen: WP_DEBUG to true, WP_DEBUG_LOG to true and WP_DEBUG_DISPLAY to false.
3 In the PHP options. In cPanel, Select PHP Version › Options, check that display_errors is off. That is how the server ships, but it may have been changed.
4 Clear the cache of your caching plugin, if you have one. Stored pages keep showing the warnings they had when they were stored.
A belt over the braces. Adding @ini_set( 'display_errors', 0 ); at the top of wp-config.php, right after the <?php, makes sure nothing shows errors even if a plugin turns them back on by itself.

Then: deal with the cause

Silencing is not curing. The warnings keep being written to the log, keep costing the server work on every visit, and a log file with thousands of identical lines eats the account’s space and file allowance.

The file path tells you whose fault it is. If the line contains wp-content/plugins/plugin-name/, that plugin is the problem. If it contains wp-content/themes/, it is the theme.

What the line says What to do
A plugin you know Update it. If it is already current and the warnings persist, the author has abandoned it: look for a replacement.
A plugin you do not use Delete it. The quickest and cheapest cure.
Hundreds of Deprecated after changing PHP The code is old for the new version. Update everything; if there is no update, go back to an earlier PHP version while you find a replacement: changing your PHP version without breaking the site.
The theme If it is a purchased theme, ask the author. If it is a child theme somebody built, that is where it is fixed.

The full log, where it lives and how to read it line by line, is in where the PHP error log is.

The side effect nobody connects to the warnings

A warning printed before the rest of the page breaks things that have nothing to do with it. PHP has already sent text to the browser, and from then on it can no longer redirect or deliver a file. The typical symptom is a headers already sent message, or an export that downloads a corrupted file, or a sign-in that never redirects.

So if something odd started at the same time as the warnings, it is probably the same story.

The rule that stays

Record everything, show nothing. It is the right combination for a live site, and it is how the server already comes configured. If you ever really need the error on screen, turn it on, reproduce it, turn it off. Minutes, not days.

Log full of warnings and no idea which one is the culprit?

Send us a few lines

SEE ALSO

WordPress hosting

Support Policy

Frequently asked questions

RECOMMENDED PRODUCT

Web hosting with cPanel

Domain and SSL included, daily backups and the panel you already know. from ₦15.000,00/mo

See plans
  • 0 Users Found This Useful
Was this answer helpful?