PHP Development

Understanding the Implications of Enabling PHP exec() Function

By the Domain India teamPublished 5 min read
Knowledge base article
Contents (5 sections)

PHP's exec() lets a script run operating-system commands, and on Domain India shared hosting it is disabled, together with the other functions that start programs. It cannot be switched on for one account, because on a shared server one hacked website with exec() could attack every other account on the machine. This page explains why, and what to do instead.

Key takeaways

exec(), shell_exec(), system(), proc_open() and popen() are disabled on our cPanel and DirectAdmin shared servers, and the restriction cannot be lifted for a single account. Most projects have a working alternative: a pure-PHP library instead of a command-line tool, running Composer with --no-scripts or on your computer, and mail() with -f instead of SMTP. If your application truly must run programs, use a VPS or the App Platform, where nothing is disabled.

For the full guide

The complete list of disabled function groups, what each one breaks and the tested workarounds are in PHP disabled functions on shared hosting.

1. What exec() does

exec() hands a command to the server's shell and returns its output. A script can use it to call tools such as ImageMagick, wkhtmltopdf, zip or git. The command runs with the same rights as your account, so anything your account can do, the script can do, and so can anyone who manages to run code through that script.

2. Why it stays disabled on shared hosting

Command injection
A form field or URL parameter that reaches exec() without strict checks lets an attacker run their own commands
Backdoors
One uploaded PHP file with exec() can download malware, start a spam run or mine cryptocurrency on your account's resources
Damage to neighbours
A spam run gets the server's IP blacklisted, and every customer on it then has email problems

Our cPanel and DirectAdmin shared servers run CloudLinux with CageFS, which gives each account its own view of the file system, and Imunify360 for malware protection. Those limit what a compromised account can see. Disabling the functions that start programs closes the door before an attacker gets that far, and keeps "one site was hacked" inside one account.

3. Can it be enabled for my account?

No. disable_functions is applied to the PHP engine on the server. A per-account setting can only add restrictions, never remove one, so ini_set(), .user.ini, .htaccess and switching PHP version all fail to restore it. On our cPanel servers the same list also applies to PHP run from the command line over SSH.

To see the list that applies to you, put <?php echo ini_get('disable_functions'); in a temporary file, open it in your browser, and delete the file afterwards. On Webuzo, check the same way or ask support.

4. What to do instead

If you used exec() forDo this instead
Resizing images with ImageMagick's command-line toolThe GD extension, or the Imagick PHP extension if it is enabled for your PHP version
Creating PDFs with wkhtmltopdfA pure-PHP library such as Dompdf, mPDF or TCPDF
Running Composer or git from a scriptRun Composer on your computer or in CI and upload the project with its vendor folder
Sending mail through sendmail or SMTPPHP mail() with the -f envelope sender, or an email API over HTTPS
Zipping files for backupsThe control panel's JetBackup backups, or a plugin that archives in pure PHP
Video or audio conversion with FFmpegA VPS or the App Platform

Working code for the mail route is in PHP sendmail settings.

5. When you need a server that runs programs

If running command-line tools is the point of your application, it needs its own environment:

  • App Platform: your app runs in its own container, so no functions are disabled. Node.js apps are detected automatically; PHP and anything else run from your own Dockerfile.
  • VPS: full root access to install any tool and set your own php.ini. It is self-managed, so updates, security and backups are your job.
App Starter
₹100/mo + GST
  • 512 MB RAM per app
  • 1 vCPU
  • 5 GB NVMe SSD
  • PostgreSQL Database
See plan details
VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details

Prices on the cards are Domain India list prices and exclude 18% GST.

Why is exec() disabled on shared hosting?

On a shared server, many accounts live on one machine. exec() lets PHP run system commands, so a single hacked website could download malware, send spam or attack other accounts. Disabling it keeps a compromise inside one account.

Can Domain India enable exec() for my account only?

No. disable_functions is set on the PHP engine and a per-account setting can only add restrictions, never remove them. Switching PHP version does not lift it either. Use a VPS or the App Platform if your application must run programs.

Which other PHP functions are disabled?

On our cPanel and DirectAdmin shared servers, exec, shell_exec, system, proc_open, popen and dl are disabled, along with other groups described in the PHP disabled functions guide. The exact list can differ by server and PHP version, so check yours with ini_get('disable_functions').

How do I check whether exec() is disabled on my hosting?

Create a temporary PHP file containing echo ini_get('disable_functions'); open it in your browser and look for exec in the output, then delete the file. function_exists('exec') returns false when it is disabled.

Ready to find the right home for your application? Read the hosting compatible technologies list, compare VPS plans and the App Platform, or open a support ticket with your exact error.

Not sure whether your app will run on shared hosting?

Send us the exact error message and what your application needs to do. We will tell you what your server allows and which plan fits.

Ask our support team

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app