# PHP magic\_quotes\_gpc setting

**URL:** <https://forums.interworx.com/t/php-magic-quotes-gpc-setting/11454>\
**Category:** Hacks / Tools / Tips / Tricks\
**Created:** [February 26, 2007, 1:45am UTC](https://forums.interworx.com/t/php-magic-quotes-gpc-setting/11454 "2007-02-26T01:45:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![system](https://forums.interworx.com/uploads/default/original/2X/4/40ab17cc34b792a0172b48ad1333b9ba9299a9a1.png) [@system](https://forums.interworx.com/u/system)\
**Post date:** [February 26, 2007, 1:45am UTC](https://forums.interworx.com/t/php-magic-quotes-gpc-setting/11454/1 "2007-02-26T01:45:41Z")

</div>

Hi,

some of my clients are reporting that Joomla gives them following warning message:

> [LEFT] Following PHP Server Settings are not optimal for Security and it is recommended to change them:

- PHP magic\_quotes\_gpc setting is `OFF` instead of `ON`Please check [the Official Joomla! Server Security post](http://www.joomla.org/security10) for more information. [/LEFT]

I haven’t touched PHP settings to make sure everything works as expected by Interworx-CP. What is the right solution and/or value for this PHP settings variable, as recommended by Interworx?

Thanks,

Muad

---

<div class="post-metadata">

**Author:** ![system](https://forums.interworx.com/uploads/default/original/2X/4/40ab17cc34b792a0172b48ad1333b9ba9299a9a1.png) [@system](https://forums.interworx.com/u/system)\
**Post date:** [February 26, 2007, 7:48am UTC](https://forums.interworx.com/t/php-magic-quotes-gpc-setting/11454/2 "2007-02-26T07:48:43Z")

</div>

This is really messy. You can turn on magic\_quotes\_gpc per-domain in the confiugration file, per diretory using .htaccess (in both cases “php\_flag magic\_quotes\_gpc On”) or in php.ini.

magic\_quotes\_gpc is an attempt to protect people from themselves. It escapes incoming data to help prevent SQL injection and such. The problem is, software that does what it should do and attempts to sanitize incoming data can cause problems if magic\_quotes\_gpc is on. Things get double escaped unless detection is used, in which case things get slightly messier 🙂

If magic\_quotes\_gpc should be on or not is a matter of opinion. I say no, others say yes.
