When a visitor uploads a file through a PHP form, PHP first writes it to a temporary folder, then your script moves it somewhere permanent. The setting that picks that temporary folder is upload_tmp_dir. Older guides tell you to change it with a php.ini, a user.ini or an .htaccess line, but on shared hosting none of those can change it, and the .htaccess route can take your whole site down.
upload_tmp_dir is a server-level PHP setting, so a .user.ini, a php.ini in your folder or the cPanel MultiPHP INI Editor cannot change it on shared hosting. You rarely need to: on Domain India's cPanel and DirectAdmin servers every account already gets its own private temporary folder. What you control is where the file goes after upload. Move it with move_uploaded_file() into a folder outside public_html. If you truly need a different temporary folder, you need a server you configure yourself, such as a VPS.
1. How PHP handles an uploaded file
Every upload goes through the same four steps:
- The browser sends the fileas part of a form submitted with
enctype="multipart/form-data". - PHP writes it to the temporary folderunder a random name such as
php8a3F2k, and records the details in$_FILES. - Your script checks it and moves itto a permanent folder with
move_uploaded_file(). - PHP deletes the temporary copywhen the request ends, if your script did not move it.
So the temporary folder only holds a file for the length of one request. The folder that matters for security, disk space and backups is the permanent one your script chooses in step 3.
2. Why you can't change upload_tmp_dir on shared hosting
PHP settings have different permission levels. Settings such as memory_limit and upload_max_filesize can be changed per folder, which is why a .user.ini file works for them. upload_tmp_dir is a system-level setting (PHP_INI_SYSTEM in the PHP manual). PHP only reads it from the server's main configuration or the PHP-FPM pool that the host manages.
| Method | Can it change upload_tmp_dir? | What happens |
|---|---|---|
| .user.ini in your folder | No | PHP ignores the line without any error |
| php.ini in your folder | No | Not read reliably on our servers, and cannot set system-level values anyway |
| cPanel MultiPHP INI Editor | No | It writes per-folder settings, which cannot hold system-level values |
| php_value in .htaccess | No | The whole site returns a 500 Internal Server Error |
| suPHP_ConfigPath in .htaccess | No | suPHP is not used; an unknown directive can also cause a 500 |
Our shared servers run PHP through PHP-FPM or CGI, not as an Apache module. Apache does not recognise php_value, php_flag or suPHP_ConfigPath, and the site returns a 500 Internal Server Error. If your site broke after following an older guide, remove those lines first. See troubleshooting the 500 Internal Server Error.
3. What our servers already do
We checked the PHP configuration on our cPanel and DirectAdmin servers on 23 September 2026. upload_tmp_dir is not set, so PHP uses the system temporary folder. Both servers run CloudLinux with CageFS, which gives every account its own private /tmp. Other accounts on the server cannot see or read your temporary upload files, which was the main reason older guides suggested moving them.
We have not measured the Webuzo server for this setting. If you host on Webuzo and need to know, ask support.
To see what your site uses, upload a small test file, open it in your browser once, then delete it:
<?php
// check-tmp.php: delete this file after you have read the output
echo 'upload_tmp_dir: ', var_export(ini_get('upload_tmp_dir'), true), "\n";
echo 'system temp dir: ', sys_get_temp_dir(), "\n";
echo 'file_uploads: ', ini_get('file_uploads'), "\n";
echo 'upload_max_filesize: ', ini_get('upload_max_filesize'), "\n";An empty upload_tmp_dir means PHP is using the system temporary folder shown on the next line. On cPanel, a cache in front of the web server can show an old response, so add ?t=1 to the address if you check again after a change.
4. Store uploads in a safe permanent folder
This is the part you control, and it is the part that decides whether uploads are safe.
- Keep the folder outside
public_html. For example/home/username/uploads. Files there cannot be opened directly from the web, so an uploaded script cannot be run by a visitor. Serve files to visitors through a PHP script that checks who is asking. - Check the upload before you move it. Test the error code, the size and the real file type, and give the file a new name. Never trust the file name or type the browser sends.
- Use normal permissions. Folders
755, files644. Never777.
A minimal, safe pattern:
<?php
$dir = '/home/username/uploads'; // outside public_html
$allowed = ['image/jpeg' => 'jpg', 'image/png' => 'png', 'application/pdf' => 'pdf'];
$f = $_FILES['document'] ?? null;
if (!$f || $f['error'] !== UPLOAD_ERR_OK) {
exit('Upload failed, error code ' . ($f['error'] ?? 'none'));
}
if ($f['size'] > 10 * 1024 * 1024) {
exit('File is larger than 10 MB');
}
$type = (new finfo(FILEINFO_MIME_TYPE))->file($f['tmp_name']);
if (!isset($allowed[$type])) {
exit('File type not allowed');
}
$name = bin2hex(random_bytes(16)) . '.' . $allowed[$type];
if (!move_uploaded_file($f['tmp_name'], $dir . '/' . $name)) {
exit('Could not save the file');
}
echo 'Saved';Replace username with your hosting account username, which is shown in the client area on your hosting service's Manage › Access tab. Create the folder first with the File Manager.
5. Temporary folders in WordPress and frameworks
Applications often have their own temporary folder, separate from PHP's upload folder, and that one you usually can change.
- WordPress uses a temporary folder for plugin and theme updates and for downloads. You can set it in
wp-config.phpwithdefine('WP_TEMP_DIR', '/home/username/tmp');. This does not change where PHP puts form uploads, and WordPress moves media uploads intowp-content/uploadsitself. - Laravel, Symfony and similar frameworks keep their own cache and temporary files inside the project, such as Laravel's
storagefolder, and receive uploads through PHP's normal temporary folder. - Upload plugins and libraries that split large files into chunks usually have a setting for where the chunks are kept. Point it at a folder outside
public_html.
6. Fixing upload errors
Most upload problems that look like a "temporary folder" problem are something else. PHP reports the cause in $_FILES['field']['error']:
| Error code | Meaning | What to do |
|---|---|---|
| 1 (UPLOAD_ERR_INI_SIZE) | Larger than upload_max_filesize | Raise the limit, see the upload limit guide |
| 2 (UPLOAD_ERR_FORM_SIZE) | Larger than the form's MAX_FILE_SIZE field | Change or remove that field |
| 3 (UPLOAD_ERR_PARTIAL) | Only part of the file arrived | Retry; check the connection and timeouts |
| 6 (UPLOAD_ERR_NO_TMP_DIR) | No temporary folder available | Contact support with the time and the page |
| 7 (UPLOAD_ERR_CANT_WRITE) | Could not write the file | Check that your account is not at its disk or file limit |
On Domain India's cPanel server, PHP accepts uploads up to 256 MB by default, and 64 MB on DirectAdmin. The details and how to raise them are in how to change the PHP upload limit. To check disk and file usage, see check hosting resource usage.
7. When you really need a different temporary folder
Some setups genuinely need it, for example very large uploads on a separate disk. That requires changing the server's PHP configuration, which only the server's administrator can do. On shared hosting that is us, and the setting applies to the whole server, so it is not something we change for one account. You can open a ticket to describe your case.
On your own VPS you control PHP completely: set upload_tmp_dir in the main php.ini, or with php_admin_value[upload_tmp_dir] in your PHP-FPM pool, make sure the folder is writable by the PHP user and not inside the website's document root, then reload PHP-FPM.
8. Where Domain India fits
Domain India's cPanel and DirectAdmin shared hosting runs every account inside its own CloudLinux environment, and every shared plan, Webuzo included, offers a choice of PHP versions. Settings such as the upload size and memory limit can be changed per site; server-level settings such as upload_tmp_dir cannot. Prices on the cards below are Domain India list prices and exclude 18% GST.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
If your application needs server-level PHP settings, a VPS gives you root access to configure PHP yourself. VPS plans are self-managed.
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
Frequently asked questions
Can I change upload_tmp_dir with a .user.ini file?
No. upload_tmp_dir is a system-level PHP setting, so PHP only reads it from the server's main configuration. A .user.ini file, a php.ini in your folder and the cPanel MultiPHP INI Editor cannot change it on shared hosting, and PHP ignores the line without an error.
Where does PHP store uploaded files on Domain India shared hosting?
On the cPanel and DirectAdmin servers, upload_tmp_dir is not set, so PHP uses the system temporary folder. CloudLinux CageFS gives each account its own private temporary folder, so other accounts cannot read your upload files. PHP deletes the temporary copy at the end of the request unless your script moves it.
Why did my site show a 500 error after I added a line to .htaccess?
Our shared servers run PHP through PHP-FPM or CGI, not as an Apache module, so Apache does not recognise php_value, php_flag or suPHP_ConfigPath lines and returns a 500 Internal Server Error. Remove those lines and use a .user.ini file or the control panel for settings that can be changed per site.
Where should I save files that visitors upload?
In a folder outside public_html, such as /home/username/uploads, using move_uploaded_file() after checking the file's size and real type and giving it a new name. Files outside public_html cannot be opened directly from the web, which stops an uploaded script from being run.
What does "Missing a temporary folder" mean?
It is PHP upload error 6, UPLOAD_ERR_NO_TMP_DIR, which means PHP could not use its temporary folder for that request. On shared hosting it is a server-side condition, so contact support with the time of the error and the page you were using.
How do I set a custom temporary upload folder on a VPS?
Set upload_tmp_dir in the main php.ini, or add php_admin_value[upload_tmp_dir] to your PHP-FPM pool, point it at a folder outside the website's document root that the PHP user can write to, and reload PHP-FPM.
Ready to set up uploads safely? Create a private folder with the File Manager, check your size limits in how to change the PHP upload limit, or compare cPanel hosting and VPS plans. If an upload still fails, open a support ticket with the error code and the page.
Tell us the page, the file size and the error code, and we will check it with you.
Open a support ticket