How to Check Whether a PHP Constant Is Defined (Without Breaking Production)

Illustrated infographic summarizing: How to Check Whether a PHP Constant Is Defined (Without Breaking Production)

By Greg Nowak. Last updated 2026-10-01.

A WordPress editor disappears in production but works on staging. Or an agency team cannot install an update that worked in its test environment. Before changing permissions or blaming a plugin, check whether a PHP constant is controlling the behaviour. The check takes minutes; deciding whether the setting should change requires knowing who owns the deployment.

Check the constant before reading its value

PHP’s defined() answers one question: does a constant with this name exist in the current runtime? It does not tell you its value. If the name is stored in a variable, use constant() only after defined() succeeds. Since PHP 8.0, asking constant() for an undefined name throws an Error.

This example checks two named WordPress settings. Run it in a controlled maintenance context that has loaded the same WordPress configuration as the affected request. It prints only those two values:

<?php

$names = ['DISALLOW_FILE_EDIT', 'DISALLOW_FILE_MODS'];

foreach ($names as $name) {
    if (!defined($name)) {
        echo $name . ': undefined' . PHP_EOL;
        continue;
    }

    echo $name . ': ' . var_export(constant($name), true) . PHP_EOL;
}

var_export() makes true, false, strings and numbers distinguishable. A plain echo can make false look like an empty value. Keep the list limited to settings relevant to the symptom; do not turn a targeted check into a public configuration dump.

Defined does not mean enabled

For a Boolean flag, undefined, false and true are different findings. defined('DISALLOW_FILE_EDIT') returns true even when that constant’s value is false. When the name is fixed and you only need to test whether the flag is active, use defined('DISALLOW_FILE_EDIT') && DISALLOW_FILE_EDIT. The second condition runs only if the first succeeds.

What you need to know Use What the result tells you
Does the name exist? defined('NAME') Presence only, regardless of value.
Is a known Boolean flag active? defined('NAME') && NAME Whether the defined value evaluates as true.
What is the value of a name in a variable? defined($name), then constant($name) The actual value, without reading an undefined constant.
Which constants exist in this runtime? get_defined_constants(true) A grouped snapshot; review it privately because values may be sensitive.
Choose the smallest check that answers the operational question.

If a flag has a string or numeric value, record the actual value and check how the application interprets it. A truthiness test alone may conceal a configuration mistake. For constants declared in a PHP namespace, pass the fully qualified name to defined() or constant(); those functions treat the name as a string rather than resolving it from your current namespace.

What the two WordPress settings change

DISALLOW_FILE_EDIT disables WordPress’s built-in plugin and theme file editors. WordPress presents this as one security measure, while noting that it does not prevent malicious files from being uploaded by other means. DISALLOW_FILE_MODS goes further: it blocks plugin and theme installation and update functions in the administration area and also disables those file editors.

That distinction matters during a handover. A team may intentionally block dashboard code editing while retaining a managed update process. Another may route all code changes through deployment and therefore block dashboard updates too. If an action is unavailable, check both constants, the affected user’s role and the site’s update process before proposing a change. An absent constant also does not prove that the action should be available; permissions and other controls may still apply.

Compare staging and production without exposing configuration

Run the same narrow check in each environment and record the environment, runtime and result. A command-line PHP process and a web request can load different bootstrap files, so compare equivalent contexts where possible. If the values differ, locate the definition in wp-config.php, environment bootstrap code or host-managed configuration. The runtime result tells you what is set, not which file or person set it.

PHP’s get_defined_constants(true) can help when you do not yet know the name: it groups currently defined constants, including a user category. Treat that output as a private investigative tool. It can include unrelated values, and it reflects only the process in which it ran. Review a relevant subset in a protected maintenance environment; avoid publishing the full array on a web page or attaching it to an unrestricted ticket.

Turn the finding into a useful decision

  1. Describe the symptom. Note the exact screen or action, user role and environment. “Plugin updates are unavailable to administrators in production” is more useful than “WordPress is broken.”
  2. Record the state. Capture whether each relevant constant is undefined, false or true, without copying unrelated configuration values.
  3. Find the owner. Ask whether the setting is an approved security policy, a deployment safeguard or leftover configuration. Check the deployment instructions before editing a live file.
  4. Make one controlled change if needed. Update the source of configuration, test the expected administration action and document the decision for the next person maintaining the site.
  5. Remove diagnostics. Delete temporary scripts or output after recording the conclusion.

The PHP check is straightforward. The harder work is making sure production behaviour matches an agreed operating model. If your team keeps rediscovering these differences during releases or handovers, Greg can help document the decisions and coordinate a clearer delivery process.

Related on GrN.dk

Need help with this kind of work?

Talk to Greg about your delivery setup Get in touch with Greg.

Sources

Seneste artikler

En AI-assistent kan svare på spørgsmål og føre kunder til booking. Her er de konkrete grænser for pris, levering, personoplysninger og kontakt med en medarbejder.

Et sikkert AI-workflow kan omsætte Meet- og Teams-transskripter til godkendte beslutninger og opgaver i Jira eller Asana – uden at slippe kontrollen.

AI kan finde opsigelsesfrister og prisreguleringer i leverandørkontrakter, sende usikre fund til godkendelse og oprette de rette påmindelser.

Sådan automatiserer danske virksomheder Gmail og Microsoft 365 med hurtig sortering, begrænsede rettigheder og menneskelig godkendelse.

Samme kunde på flere kort i HubSpot? Se, hvordan CVR-match, AI-forslag og menneskelig godkendelse kan bruges til at rydde op med styr på felter, relationer og kundehistorik.

Få en ugentlig marketingrapport fra GA4 og Google Ads med kontrollerede beregninger, tydelige dataforbehold og et kort AI-udkast, der hjælper jer på mandagsmødet.

Brug AI til webshoppens alt-tekster med en overskuelig pilot: kortlæg billederne, få danske forslag, og kontrollér resultatet i WordPress og WooCommerce.

AI-baseret ticketanalyse kan afsløre gentagne klager, produktfejl og huller i dokumentationen – uden at virksomheden behøver endnu en chatbot.

OpenSSH 10 fjerner DSA og advarer om nøgleudveksling, der ikke er post-kvantesikker. Her får du en metode til at afgrænse SFTP-oprydningen uden at svække alle SSH-forbindelser.

Botforespørgsler overstiger nu menneskelig webtrafik. Lær at auditere AI-crawlere, fastsætte regler på stiniveau, håndhæve robots.txt og måle det forretningsmæssige afkast.