“Call to undefined function get_magic_quotes_gpc()” in WordPress: the fix

By CompatNav · Published · Last reviewed · 3 min read

Short answer

It’s a fatal error from PHP 8.0 and later: an old plugin or theme asks PHP whether “magic quotes” are on, with a function PHP removed in 8.0. The page stops and WordPress shows “There has been a critical error on this website”. The good news: on PHP 7.4 the function always answered “no”, so the code around it never did anything, and the fix is simply to remove the check. Update the plugin or theme; a check that reads code finds it before you switch.

The message, exactly

An old contact-form plugin checks for magic quotes before cleaning a message. On PHP 7.4 that gives a deprecation notice; on PHP 8.0 the page stops:

wp-content/plugins/old-contact/old-contact.php

<?php
$message = 'It\'s ready';
if (get_magic_quotes_gpc()) {
    $message = stripslashes($message);
}
echo $message, "\n";

Output on PHP 7.4.33

Deprecated: Function get_magic_quotes_gpc() is deprecated in /var/www/html/wp-content/plugins/old-contact/old-contact.php on line 3
It's ready

Output on PHP 8.0.30the script stopped

Fatal error: Uncaught Error: Call to undefined function get_magic_quotes_gpc() in /var/www/html/wp-content/plugins/old-contact/old-contact.php:3
Stack trace:
#0 {main}
  thrown in /var/www/html/wp-content/plugins/old-contact/old-contact.php on line 3

php.net’s page for the function: “This function has been DEPRECATED as of PHP 7.4.0, and REMOVED as of PHP 8.0.0.” (php.net)

Why removing the check is safe

“Magic quotes” was an old PHP setting that added a backslash before every quote in form data. PHP switched it off long before 7.4, and get_magic_quotes_gpc() only reported its state. For PHP 7.4, php.net says the functions “are deprecated. They always return false.” (php.net)

So in the example, stripslashes() never ran on PHP 7.4: the message came out the same with or without the check. Removing the check keeps exactly that behaviour; the fixed version below gives the same output on PHP 7.4, 8.0 and 8.5.

Fix it, in order

  1. Site down? Switch PHP back in your hosting panel, or pause the plugin through the link in WordPress’s email. The critical error guide shows both.
  2. Find the plugin or theme: the folder after wp-content/plugins/ or wp-content/themes/ in the message, here old-contact.
  3. Update it (Dashboard → Updates).
  4. Already on the latest version? Send the full message to its developer. Code that still calls this function hasn’t been updated for PHP 8; if nobody maintains it, replace it.

Found before you switch

The call is in the code itself, so a check that reads code finds it while your site still runs PHP 7.4:

Old code that calls it often has other PHP 8.0 removals nearby, such as each() or create_function().

Key takeaways

  • get_magic_quotes_gpc() was deprecated in PHP 7.4 and removed in PHP 8.0; on PHP 8 every call is a fatal error.
  • On PHP 7.4 it always returned false, so the code it guarded never ran: removing the check changes nothing.
  • WordPress adds slashes to form data itself, whatever PHP does; plugins remove them with wp_unslash().
  • The path in the message names the plugin or theme; update it or send the message to its developer.
  • A check that reads code finds every call before you upgrade.

Frequently asked questions

What were magic quotes?

An old PHP feature that added backslashes before quotes in form data automatically. It was meant to protect databases; PHP stopped using it long ago, and get_magic_quotes_gpc() only reported whether it was on.

Is removing the check really safe?

Yes, as far as PHP goes: php.net says the function always returned false on PHP 7.4, so the code inside the check never ran. What the plugin does with WordPress’s own slashes is a separate question for its developer.

Is get_magic_quotes_runtime() the same?

Yes. Both functions were deprecated in PHP 7.4 and removed in PHP 8.0.

Check your own site before you upgrade

CompatNav is a free WordPress plugin. It reads the code of your plugins and themes on your own server and tells you, in plain words, what will break and what will only show notices on the PHP version you choose. It never changes your code. It can’t see problems that only appear while code runs with real data, so a quick check of your site after the upgrade still matters.

Get CompatNav on wordpress.org How it works

Sources

About the code examples: each output is the real output of the code shown, run with the official PHP builds, without a php.ini, with all errors reported and displayed. Only the file path was replaced by a neutral server path.