Debug mode is on — and your visitors might see technical error messages instead of your content. This is like leaving your diary open on a park bench.
Why This Matters
When WP_DEBUG is set to true, WordPress displays:
- PHP errors and warnings directly on your pages
- Database query information that reveals your table structure
- File paths showing your server's directory layout
- Deprecated function notices from plugins and themes
This information is gold for attackers. It tells them exactly what software you're running, where files are stored, and what potential vulnerabilities exist.
It also looks unprofessional to visitors.
Expert Insight: Running a manual audit for every security risk is exhausting. Dravasite automates this by scanning your entire environment in seconds, catching exposures like active debug modes and outdated configurations before they become a problem.
How to Fix It
Safe Practice: Before making any technical changes, ensure you have a full backup of your site (files and database) via your hosting control panel or a dedicated plugin like UpdraftPlus.
Step 1: Access wp-config.php
Connect to your site via FTP, File Manager (in your hosting panel), or SSH.
Find wp-config.php in your WordPress root directory.
Step 2: Find and Change the Debug Line
Look for this line:
define('WP_DEBUG', true);Change it to:
define('WP_DEBUG', false);Save the file. That's it — errors will stop showing immediately.
Step 3: Set Up Proper Debug Logging (Optional)
If you need to debug issues without exposing errors to visitors, use the log-only mode:
define('WP_DEBUG', true);
define('WP_DEBUG_LOG', true);
define('WP_DEBUG_DISPLAY', false);This writes errors to /wp-content/debug.log instead of showing them on screen. You can review the log file via FTP or SSH.
Important: Delete or clear
debug.logregularly — it can grow large and may contain sensitive information.
What to Watch For
- Some hosting providers override
WP_DEBUGat the server level. If changingwp-config.phpdoesn't work, check your hosting panel for a PHP debug setting. - If you're working with a developer, they may need debug mode on temporarily. Ask them to use
WP_DEBUG_LOGinstead ofWP_DEBUG_DISPLAY. - Staging/development environments should keep
WP_DEBUGon — it's only a problem on production (live) sites.