{"id":9737,"date":"2026-06-03T09:56:45","date_gmt":"2026-06-03T07:56:45","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=9737"},"modified":"2026-06-03T09:56:46","modified_gmt":"2026-06-03T07:56:46","slug":"how-does-the-open_basedir-option-work-and-what-is-it-used-for","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-the-open_basedir-option-work-and-what-is-it-used-for\/","title":{"rendered":"How Does the open_basedir Option Work and What Is It Used For?"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">The <code>open_basedir<\/code> option is a security mechanism built into PHP that restricts scripts from accessing files outside designated directories.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By default, <code>open_basedir<\/code> is enabled for every newly created website in the mybox Panel. Its purpose is to increase security by limiting PHP scripts to operating only within the directory structure assigned to a specific website.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-the-open_basedir-option-work-and-what-is-it-used-for\/#How_Does_open_basedir_Work\" >How Does open_basedir Work?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-the-open_basedir-option-work-and-what-is-it-used-for\/#Example_Error_Message\" >Example Error Message<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-the-open_basedir-option-work-and-what-is-it-used-for\/#Why_Is_open_basedir_Important\" >Why Is open_basedir Important?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-the-open_basedir-option-work-and-what-is-it-used-for\/#Example\" >Example<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-the-open_basedir-option-work-and-what-is-it-used-for\/#Common_Situations_Where_Errors_Occur\" >Common Situations Where Errors Occur<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-the-open_basedir-option-work-and-what-is-it-used-for\/#Benefits_of_open_basedir\" >Benefits of open_basedir<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-does-the-open_basedir-option-work-and-what-is-it-used-for\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_Does_open_basedir_Work\"><\/span>How Does open_basedir Work?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<\/div>\n\n<div id=\"mybox-1704915170\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">When a PHP script attempts to access a file using functions such as:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>fopen()\nfile_get_contents()\ninclude()\nrequire()\nreadfile()\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">the PHP interpreter first checks whether the target file is located within the directories allowed by the <code>open_basedir<\/code> configuration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the file is located within the permitted path, the operation proceeds normally.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the script attempts to access a file outside the allowed directory structure, PHP blocks the request and generates an error.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Example_Error_Message\"><\/span>Example Error Message<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A typical error message looks like this:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Warning: open_basedir restriction in effect\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This indicates that the script attempted to access a file outside the directories permitted by the <code>open_basedir<\/code> policy.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_Is_open_basedir_Important\"><\/span>Why Is open_basedir Important?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The primary purpose of <code>open_basedir<\/code> is to improve security in shared hosting environments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Without this restriction, a vulnerable or poorly written script could potentially attempt to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Access files belonging to another website.<\/li>\n\n\n\n<li>Read sensitive server configuration files.<\/li>\n\n\n\n<li>Access private application data.<\/li>\n\n\n\n<li>Retrieve information that should not be available to the website.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">By restricting file access to the website&#8217;s own directory structure, <code>open_basedir<\/code> helps prevent these types of attacks.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Example\"><\/span>Example<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Assume your website is located in:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>\/home\/user\/example.com\/public_html\/\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The following operation would be allowed:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$file = fopen('\/home\/user\/example.com\/public_html\/data.txt', 'r');\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">However, an attempt to access a file outside the website directory:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>$file = fopen('\/etc\/passwd', 'r');\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">would fail and generate an <code>open_basedir<\/code> error.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Common_Situations_Where_Errors_Occur\"><\/span>Common Situations Where Errors Occur<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">You may encounter <code>open_basedir<\/code> warnings when:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Installing poorly configured plugins.<\/li>\n\n\n\n<li>Migrating a website from another hosting provider.<\/li>\n\n\n\n<li>Using incorrect file paths in custom scripts.<\/li>\n\n\n\n<li>Running applications that expect unrestricted server access.<\/li>\n\n\n\n<li>Using cache or backup plugins configured with invalid paths.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">In most cases, correcting the file path resolves the issue.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Benefits_of_open_basedir\"><\/span>Benefits of open_basedir<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Improves website security.<\/li>\n\n\n\n<li>Prevents unauthorized file access.<\/li>\n\n\n\n<li>Helps isolate websites hosted on the same server.<\/li>\n\n\n\n<li>Reduces the impact of vulnerable PHP scripts.<\/li>\n\n\n\n<li>Protects sensitive system files and data.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The <code>open_basedir<\/code> option is a PHP security feature that limits file access to specific directories assigned to a website. If a script attempts to access files outside those directories, PHP blocks the operation and returns an error such as:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>Warning: open_basedir restriction in effect\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This protection helps prevent unauthorized access to files and improves the overall security of websites hosted on the server.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[125],"manual_kb_tag":[4902,4903,4904,4905,4906,4907,4908,4909,4910,4911],"class_list":["post-9737","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-websites","manual_kb_tag-open_basedir","manual_kb_tag-php_security","manual_kb_tag-shared_hosting_security","manual_kb_tag-file_access_restriction","manual_kb_tag-unauthorized_file_access","manual_kb_tag-website_isolation","manual_kb_tag-server_security","manual_kb_tag-open_basedir_error","manual_kb_tag-open_basedir_restriction","manual_kb_tag-file_path_errors"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/9737","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/9737\/revisions"}],"predecessor-version":[{"id":9742,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/9737\/revisions\/9742"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=9737"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=9737"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=9737"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}