{"id":1404,"date":"2026-10-07T13:20:13","date_gmt":"2026-10-07T13:20:13","guid":{"rendered":"https:\/\/www.ahosting.net\/blog\/?p=1404"},"modified":"2026-10-07T14:33:20","modified_gmt":"2026-10-07T14:33:20","slug":"log-errors-to-a-potentially-public-file","status":"publish","type":"post","link":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/","title":{"rendered":"Log Errors to a Potentially Public File? What Site Health Checks"},"content":{"rendered":"\n<script type=\"application\/ld+json\">{\"@context\": \"https:\/\/schema.org\", \"@type\": \"FAQPage\", \"mainEntity\": [{\"@type\": \"Question\", \"name\": \"Why does Site Health still say potentially public file after I moved debug.log?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"In practice, the check never looks at the file. Site Health shows the label whenever WP_DEBUG and WP_DEBUG_LOG are both on. Moving the log out of the WordPress folder only changes the grade from critical to recommended, because the grade depends on whether the path starts with the WordPress folder. The label clears only when logging is off, so turn WP_DEBUG off once you have what you need.\"}}, {\"@type\": \"Question\", \"name\": \"What does log errors to a potentially public file mean in WordPress in 2026?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"In other words, WP_DEBUG and WP_DEBUG_LOG are both set to true in wp-config.php while error display is off. In WordPress 7.1 Site Health reads those settings and nothing else. It does not check whether the log exists or whether a visitor can download it. The warning is critical when the log sits inside the WordPress folder and recommended when it sits anywhere else.\"}}, {\"@type\": \"Question\", \"name\": \"Potentially public file vs display errors to site visitors: which warning is worse?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Specifically, display errors to site visitors is worse, because every visitor sees the errors in the page itself. Both labels come from the same test. WP_DEBUG_DISPLAY defaults to true, so a site that turns on WP_DEBUG without turning display off gets the display label, graded critical. The potentially public file label only appears once display is off, and it describes a file someone has to request by its address, which is the same default address on every site.\"}}, {\"@type\": \"Question\", \"name\": \"Can a potentially public file protected by htaccess still show as critical?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Indeed it can. Site Health grades the log by its path alone, and a log in wp-content starts with the WordPress folder, so it is graded critical whether or not a rule blocks it. A deny rule that returns 403 does protect the file. It does not change the grade, and only turning logging off or moving the log changes what Site Health reports.\"}}, {\"@type\": \"Question\", \"name\": \"Does turning off WP_DEBUG delete the potentially public file in wp-content?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"In fact, no. Setting WP_DEBUG to false stops WordPress from writing new entries and turns the Site Health result green, but the debug.log already on disk stays where it is, and the web server keeps serving it. Download it if you still need it, then delete it in File Manager. Request its address once more afterwards; a 404 confirms that it is gone.\"}}, {\"@type\": \"Question\", \"name\": \"WP_DEBUG_LOG true vs a custom path: which one is safer on a live site?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Typically a custom path outside the folder your domain serves. Set to true, WP_DEBUG_LOG writes to wp-content\/debug.log, which the web server can deliver to anyone who requests it. Set to a full path in your home folder, it writes somewhere no address points to, and Site Health lowers the grade to recommended. Logging still writes on every error, so turn it off when you are done.\"}}, {\"@type\": \"Question\", \"name\": \"How do I set a custom debug log path in WordPress 7.1 in 2026?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"First and foremost, create the folder, because PHP creates the log file but not the folder that holds it. Then set WP_DEBUG_LOG to the full path in wp-config.php, above the line that says to stop editing, for example \/home\/ followed by your cPanel username and \/wp-logs\/debug.log. Trigger a page load, confirm the file appears, and check that Site Health now grades the warning as recommended.\"}}, {\"@type\": \"Question\", \"name\": \"Where should I put debug.log on AHosting shared hosting in 2026?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Above all, outside public_html, in a folder of its own in your home folder. On our servers PHP runs as your own cPanel user inside CageFS, so WordPress can write to a folder there with no permission changes, and no address on the web points to it. Avoid other folders a domain on the account serves from, and turn logging off when the debugging is finished.\"}}, {\"@type\": \"Question\", \"name\": \"Can AHosting support help me read the log behind a potentially public file warning?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Notably, the warning itself needs no ticket: turning WP_DEBUG off clears it, and deleting the old file closes the exposure. If the log keeps filling with the same error and you cannot tell which plugin writes it, open a ticket with the first lines of the log and we will look at it with you.\"}}, {\"@type\": \"Question\", \"name\": \"Do I need an AHosting VPS to debug WordPress with errors displayed in 2026?\", \"acceptedAnswer\": {\"@type\": \"Answer\", \"text\": \"Fortunately not for this warning. Logging to a file outside public_html works on a shared plan and keeps errors away from visitors. A VPS makes sense when you want a separate staging copy where errors can be displayed safely, with the environment type set to development, or when you want to choose the PHP logging setup for the whole server yourself.\"}}]}<\/script>\n\n\n<div class=\"wp-block-aioseo-table-of-contents\"><ul><li><a class=\"aioseo-toc-item\" href=\"#aioseo-what-log-errors-to-a-potentially-public-file-actually-means\">What \u201cLog Errors to a Potentially Public File\u201d Actually Means<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#aioseo-three-settings-checked-and-no-look-at-the-file\">Three Settings Checked, and No Look at the File<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#aioseo-critical-or-recommended-which-badge-you-get\">Critical or Recommended: Which Badge You Get<\/a><\/li><\/ul><\/li><li><a class=\"aioseo-toc-item\" href=\"#aioseo-why-moving-debug-log-does-not-clear-the-potentially-public-file-warning\">Why Moving debug.log Does Not Clear the Potentially Public File Warning<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#aioseo-the-grade-follows-a-path-prefix\">The Grade Follows a Path Prefix<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#aioseo-a-protected-log-still-reads-as-critical\">A Protected Log Still Reads as Critical<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#aioseo-recommended-does-not-mean-private\">Recommended Does Not Mean Private<\/a><\/li><\/ul><\/li><li><a class=\"aioseo-toc-item\" href=\"#aioseo-display-errors-to-site-visitors-vs-a-potentially-public-file\">Display Errors to Site Visitors vs a Potentially Public File<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#aioseo-why-wp_debug_display-hides-the-potentially-public-file-label\">Why WP_DEBUG_DISPLAY Hides the Potentially Public File Label<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#aioseo-the-development-environment-exception\">The Development Environment Exception<\/a><\/li><\/ul><\/li><li><a class=\"aioseo-toc-item\" href=\"#aioseo-is-your-potentially-public-file-actually-public-test-it\">Is Your Potentially Public File Actually Public? Test It<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#aioseo-what-a-200-403-or-404-means\">What a 200, 403 or 404 Means<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#aioseo-what-a-wordpress-debug-log-gives-away\">What a WordPress Debug Log Gives Away<\/a><\/li><\/ul><\/li><li><a class=\"aioseo-toc-item\" href=\"#aioseo-how-to-fix-a-potentially-public-file-warning-in-order\">How to Fix a Potentially Public File Warning, in Order<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#aioseo-grade-your-potentially-public-file-setup\">Grade Your Potentially Public File Setup<\/a><\/li><\/ul><\/li><li><a class=\"aioseo-toc-item\" href=\"#aioseo-potentially-public-file-warnings-on-ahosting-servers\">Potentially Public File Warnings on AHosting Servers<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#aioseo-where-to-put-debug-log-on-ahosting\">Where to Put debug.log on AHosting<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#aioseo-a-log-left-running-never-stops-growing\">A Log Left Running Never Stops Growing<\/a><\/li><\/ul><\/li><li><a class=\"aioseo-toc-item\" href=\"#aioseo-a-practical-checklist-for-the-potentially-public-file-warning\">A Practical Checklist for the Potentially Public File Warning<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#faq-log-errors-to-a-potentially-public-file\">Frequently Asked Questions: Log Errors to a Potentially Public File<\/a><ul><li><a class=\"aioseo-toc-item\" href=\"#faq-why-does-site-health-still-say-potentially-public-file-after-i-moved-debug-log\">Why does Site Health still say potentially public file after I moved debug.log?<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#faq-what-does-log-errors-to-a-potentially-public-file-mean-in-wordpress-in-2026\">What does log errors to a potentially public file mean in WordPress in 2026?<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#faq-potentially-public-file-vs-display-errors-to-site-visitors-which-warning-is-worse\">Potentially public file vs display errors to site visitors: which warning is worse?<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#faq-can-a-potentially-public-file-protected-by-htaccess-still-show-as-critical\">Can a potentially public file protected by htaccess still show as critical?<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#faq-does-turning-off-wp-debug-delete-the-potentially-public-file-in-wp-content\">Does turning off WP_DEBUG delete the potentially public file in wp-content?<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#faq-wp-debug-log-true-vs-a-custom-path-which-one-is-safer-on-a-live-site\">WP_DEBUG_LOG true vs a custom path: which one is safer on a live site?<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#faq-how-do-i-set-a-custom-debug-log-path-in-wordpress-7-1-in-2026\">How do I set a custom debug log path in WordPress 7.1 in 2026?<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#faq-where-should-i-put-debug-log-on-ahosting-shared-hosting-in-2026\">Where should I put debug.log on AHosting shared hosting in 2026?<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#faq-can-ahosting-support-help-me-read-the-log-behind-a-potentially-public-file-warning\">Can AHosting support help me read the log behind a potentially public file warning?<\/a><\/li><li><a class=\"aioseo-toc-item\" href=\"#faq-do-i-need-an-ahosting-vps-to-debug-wordpress-with-errors-displayed-in-2026\">Do I need an AHosting VPS to debug WordPress with errors displayed in 2026?<\/a><\/li><\/ul><\/li><\/ul><\/div>\n\n\n<div class=\"ah-tldr\">\n  <span class=\"ah-tldr-badge\">TL;DR<\/span>\n  <p>Your site is set to log errors to a potentially public file means two settings in wp-config.php, WP_DEBUG and WP_DEBUG_LOG, are both on while error display is off. Site Health never checked whether the log can be downloaded. The grade depends only on whether the log&#8217;s path sits inside your WordPress folder, so moving the file lowers the warning to recommended but never clears it. Read what you need, turn WP_DEBUG off, then delete the old debug.log, because turning logging off does not remove the file.<\/p>\n<\/div>\n\n\n\n<h2 id=\"aioseo-what-log-errors-to-a-potentially-public-file-actually-means\" class=\"wp-block-heading\">What \u201cLog Errors to a Potentially Public File\u201d Actually Means<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Your site is set to log errors to a potentially public file<\/em> is the Site Health warning that can turn up long after a fix, once nobody remembers switching debugging on. It sounds as if WordPress found your error log on the open web. Read against the WordPress 7.1.2 code that writes it, the message is much narrower: Site Health has not found the file, and it has not tried to.<\/p>\n\n\n\n<figure class=\"wp-block-audio\"><audio preload=\"none\" controls src=\"https:\/\/www.ahosting.net\/blog\/wp-content\/uploads\/2026\/10\/PODCAST-log-errors-to-a-potentially-public-file.m4a\"><\/audio><figcaption class=\"wp-element-caption\">Listen: Site Health reads two settings and a path, never the log itself, so only switching debugging off turns it green. By Matt Chrust, Director of Business Development, AHosting.<\/figcaption><\/figure>\n\n\n\n<h3 id=\"aioseo-three-settings-checked-and-no-look-at-the-file\" class=\"wp-block-heading\">Three Settings Checked, and No Look at the File<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The test behind the warning, listed in Site Health as <em>Debugging enabled<\/em>, reads three constants from <code>wp-config.php<\/code>. When <code>WP_DEBUG<\/code> and <code>WP_DEBUG_LOG<\/code> are both on, and <code>WP_DEBUG_DISPLAY<\/code> is off, the label reads log errors to a potentially public file. The test does not open the log, does not check that it exists and does not request it over the web. Its own description calls the file potentially available to all users, and potentially is the operative word.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Set to true, <code>WP_DEBUG_LOG<\/code> sends every PHP error, warning and notice to <code>debug.log<\/code> in the content folder, usually <code>wp-content\/debug.log<\/code>. As <a href=\"https:\/\/developer.wordpress.org\/advanced-administration\/debug\/debug-wordpress\/\" target=\"_blank\" rel=\"noopener\">the WordPress debugging handbook<\/a> explains, you can instead give it a full file path to have the log saved elsewhere. That one option is the whole difference between the two grades the warning can carry.<\/p>\n\n\n\n<h3 id=\"aioseo-critical-or-recommended-which-badge-you-get\" class=\"wp-block-heading\">Critical or Recommended: Which Badge You Get<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Site Health files the warning under its Security badge, and it can carry either grade. It is critical when the log path starts with the WordPress folder, the path WordPress calls <code>ABSPATH<\/code>, and recommended when it starts anywhere else. The default <code>wp-content\/debug.log<\/code> sits inside that folder, so most sites see it as a critical issue. Neither grade means anything is broken. The site keeps working; the warning is about who else might be able to read your errors.<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<div class=\"ah-yt\" data-id=\"U3ydXIRHhOQ\" data-title=\"Log Errors to a Potentially Public File? WordPress Fix (2026)\"><img src=\"https:\/\/i.ytimg.com\/vi\/U3ydXIRHhOQ\/hqdefault.jpg\" alt=\"\" width=\"480\" height=\"360\" loading=\"lazy\" decoding=\"async\"><button type=\"button\" class=\"ah-yt-play\" aria-label=\"Play video: Log Errors to a Potentially Public File? WordPress Fix (2026)\"><span aria-hidden=\"true\"><\/span><\/button><\/div>\n<\/div><\/figure>\n\n\n\n<h2 id=\"aioseo-why-moving-debug-log-does-not-clear-the-potentially-public-file-warning\" class=\"wp-block-heading\">Why Moving debug.log Does Not Clear the Potentially Public File Warning<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The most common surprise is that moving the log changes nothing visible. One reporter on the WordPress bug tracker put it plainly: setting the log path to a system folder should fix it, but does not. The code explains why. This is the full grading, read from the test in the current release.<\/p>\n\n\n\n<figure class=\"wp-block-table ah-ladder\"><table><thead><tr><th>Settings in wp-config.php<\/th><th>Label Site Health shows<\/th><th>Grade<\/th><\/tr><\/thead><tbody><tr><td>WP_DEBUG false or not set (anything else ignored)<\/td><td>Not set to output debug information<\/td><td>Good<\/td><\/tr><tr><td>WP_DEBUG true, WP_DEBUG_LOG false, display off<\/td><td>Not set to output debug information<\/td><td>Good<\/td><\/tr><tr><td>WP_DEBUG true, WP_DEBUG_DISPLAY true or not set<\/td><td>Display errors to site visitors<\/td><td>Critical (recommended in development)<\/td><\/tr><tr><td>WP_DEBUG true, WP_DEBUG_LOG true, display off<\/td><td>Log errors to a potentially public file<\/td><td>Critical<\/td><\/tr><tr><td>WP_DEBUG true, WP_DEBUG_LOG a path inside the WordPress folder, display off<\/td><td>Log errors to a potentially public file<\/td><td>Critical<\/td><\/tr><tr><td>WP_DEBUG true, WP_DEBUG_LOG a path outside the WordPress folder, display off<\/td><td>Log errors to a potentially public file<\/td><td>Recommended<\/td><\/tr><\/tbody><\/table><figcaption class=\"wp-element-caption\">What WordPress 7.1 Site Health reports for each debug setting \u2014 label and grade, read from the core Debugging enabled test.<\/figcaption><\/figure>\n\n\n\n<div class=\"ah-infographic\">\n  <svg viewBox=\"0 0 720 420\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Folder tree of a cPanel account showing how Site Health grades the potentially public file warning. A log inside the WordPress folder is graded critical, a log anywhere else is graded recommended, and the grade says nothing about whether a visitor can download the file.\">\n    <title>The potentially public file grade follows the path, not the exposure<\/title>\n    <desc>A folder tree starting at the account home folder. Inside it, public_html is the folder the domain serves. WordPress is installed in public_html\/blog, which is ABSPATH. The default log at public_html\/blog\/wp-content\/debug.log is inside ABSPATH and graded critical, and a visitor can download it unless a rule blocks it. A log at public_html\/logs\/debug.log is outside ABSPATH and graded recommended, yet a visitor can still download it. A log at home\/wp-logs\/debug.log is outside ABSPATH and outside public_html, graded recommended, and no address points to it. Only turning WP_DEBUG off turns the result green.<\/desc>\n    <rect x=\"0\" y=\"0\" width=\"720\" height=\"420\" fill=\"#0f172a\"\/>\n    <text x=\"32\" y=\"40\" fill=\"#ffffff\" font-family=\"Helvetica, Arial, sans-serif\" font-size=\"19\" font-weight=\"700\">The grade follows the path, not the exposure.<\/text>\n    <text x=\"32\" y=\"63\" fill=\"#eef3ff\" font-family=\"Helvetica, Arial, sans-serif\" font-size=\"13\">WordPress 7.1.2, WP_DEBUG and WP_DEBUG_LOG on, display off. WordPress installed in \/blog.<\/text>\n    <text x=\"32\" y=\"104\" fill=\"#93c5fd\" font-family=\"Menlo, monospace\" font-size=\"14\" font-weight=\"700\">\/home\/user\/<\/text>\n    <rect x=\"52\" y=\"118\" width=\"420\" height=\"190\" fill=\"#1e293b\" stroke=\"#334155\" stroke-width=\"2\"\/>\n    <text x=\"66\" y=\"142\" fill=\"#eef3ff\" font-family=\"Menlo, monospace\" font-size=\"13\">public_html\/<\/text>\n    <text x=\"196\" y=\"142\" fill=\"#94a3b8\" font-family=\"Helvetica, Arial, sans-serif\" font-size=\"11\">served by the domain<\/text>\n    <rect x=\"76\" y=\"156\" width=\"380\" height=\"74\" fill=\"#0f172a\" stroke=\"#2563eb\" stroke-width=\"2\"\/>\n    <text x=\"90\" y=\"178\" fill=\"#eef3ff\" font-family=\"Menlo, monospace\" font-size=\"13\">blog\/  (ABSPATH)<\/text>\n    <text x=\"104\" y=\"204\" fill=\"#fca5a5\" font-family=\"Menlo, monospace\" font-size=\"13\">wp-content\/debug.log<\/text>\n    <text x=\"104\" y=\"221\" fill=\"#94a3b8\" font-family=\"Helvetica, Arial, sans-serif\" font-size=\"11\">critical, downloadable unless a rule blocks it<\/text>\n    <text x=\"90\" y=\"262\" fill=\"#fcd34d\" font-family=\"Menlo, monospace\" font-size=\"13\">logs\/debug.log<\/text>\n    <text x=\"90\" y=\"280\" fill=\"#94a3b8\" font-family=\"Helvetica, Arial, sans-serif\" font-size=\"11\">recommended, and still downloadable<\/text>\n    <rect x=\"52\" y=\"324\" width=\"420\" height=\"44\" fill=\"#1e293b\" stroke=\"#22c55e\" stroke-width=\"2\"\/>\n    <text x=\"66\" y=\"344\" fill=\"#86efac\" font-family=\"Menlo, monospace\" font-size=\"13\">wp-logs\/debug.log<\/text>\n    <text x=\"66\" y=\"360\" fill=\"#94a3b8\" font-family=\"Helvetica, Arial, sans-serif\" font-size=\"11\">recommended, and no address points to it<\/text>\n    <rect x=\"500\" y=\"118\" width=\"190\" height=\"250\" fill=\"#1e293b\" stroke=\"#334155\" stroke-width=\"2\"\/>\n    <text x=\"514\" y=\"144\" fill=\"#ffffff\" font-family=\"Helvetica, Arial, sans-serif\" font-size=\"13\" font-weight=\"700\">What Site Health reads<\/text>\n    <text x=\"514\" y=\"170\" fill=\"#eef3ff\" font-family=\"Helvetica, Arial, sans-serif\" font-size=\"12\">Does the log path start<\/text>\n    <text x=\"514\" y=\"187\" fill=\"#eef3ff\" font-family=\"Helvetica, Arial, sans-serif\" font-size=\"12\">with ABSPATH?<\/text>\n    <text x=\"514\" y=\"215\" fill=\"#fca5a5\" font-family=\"Helvetica, Arial, sans-serif\" font-size=\"12\">Yes: critical<\/text>\n    <text x=\"514\" y=\"235\" fill=\"#fcd34d\" font-family=\"Helvetica, Arial, sans-serif\" font-size=\"12\">No: recommended<\/text>\n    <text x=\"514\" y=\"270\" fill=\"#94a3b8\" font-family=\"Helvetica, Arial, sans-serif\" font-size=\"12\">It never requests<\/text>\n    <text x=\"514\" y=\"287\" fill=\"#94a3b8\" font-family=\"Helvetica, Arial, sans-serif\" font-size=\"12\">the file over the web.<\/text>\n    <text x=\"514\" y=\"322\" fill=\"#86efac\" font-family=\"Helvetica, Arial, sans-serif\" font-size=\"12\">Green only with<\/text>\n    <text x=\"514\" y=\"339\" fill=\"#86efac\" font-family=\"Helvetica, Arial, sans-serif\" font-size=\"12\">WP_DEBUG off.<\/text>\n    <text x=\"32\" y=\"400\" fill=\"#94a3b8\" font-family=\"Helvetica, Arial, sans-serif\" font-size=\"12\">If WordPress sits directly in public_html, public_html\/logs starts with ABSPATH too, and is graded critical.<\/text>\n  <\/svg>\n<\/div>\n\n\n\n<h3 id=\"aioseo-the-grade-follows-a-path-prefix\" class=\"wp-block-heading\">The Grade Follows a Path Prefix<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The test compares the start of PHP\u2019s error log setting with <code>ABSPATH<\/code>, and nothing more. A log outside the WordPress folder is graded recommended, but the label stays, because the label depends only on the two constants being on. So no log location turns the result green. The only green is <code>WP_DEBUG<\/code> off. Ticket <a href=\"https:\/\/core.trac.wordpress.org\/ticket\/64071\" target=\"_blank\" rel=\"noopener\">#64071 on WordPress Trac<\/a> asks for the test to treat a log outside the WordPress folder as safe. It is still open and marked for a future release, so in 7.1.2 the label remains.<\/p>\n\n\n\n<h3 id=\"aioseo-a-protected-log-still-reads-as-critical\" class=\"wp-block-heading\">A Protected Log Still Reads as Critical<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The reverse also holds. A log in <code>wp-content<\/code> protected by a deny rule, so that a request for it returns an error, still starts with the WordPress folder and is still graded critical. The rule really does protect the file. Site Health simply has no way of knowing it is there, because it never sends a request to find out.<\/p>\n\n\n\n<h3 id=\"aioseo-recommended-does-not-mean-private\" class=\"wp-block-heading\">Recommended Does Not Mean Private<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The prefix test can also err the other way. Say WordPress is installed in <code>public_html\/blog\/<\/code> and the log is moved to <code>public_html\/logs\/<\/code>. That path does not start with the WordPress folder, so Site Health grades it recommended, yet the folder is still inside <code>public_html<\/code>, and the web server will deliver the file to anyone who asks for it. The grade measures a path. Whether the file can be downloaded is something you have to test.<\/p>\n\n\n\n<h2 id=\"aioseo-display-errors-to-site-visitors-vs-a-potentially-public-file\" class=\"wp-block-heading\">Display Errors to Site Visitors vs a Potentially Public File<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The same test has a second label, <em>Your site is set to display errors to site visitors<\/em>, and it is the worse of the two. It means errors are printed into the pages every visitor loads, rather than written to a file someone would have to know to request. Site Health grades it critical.<\/p>\n\n\n\n<h3 id=\"aioseo-why-wp_debug_display-hides-the-potentially-public-file-label\" class=\"wp-block-heading\">Why WP_DEBUG_DISPLAY Hides the Potentially Public File Label<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress defines <code>WP_DEBUG_DISPLAY<\/code> as true unless you set it yourself, and <a href=\"https:\/\/developer.wordpress.org\/reference\/functions\/wp_debug_mode\/\" target=\"_blank\" rel=\"noopener\">the code reference for wp_debug_mode()<\/a> confirms that WordPress then forces errors to be displayed. When the display setting is true, the test overwrites the log label with the display label. So a site that turns on <code>WP_DEBUG<\/code> and <code>WP_DEBUG_LOG<\/code> and stops there sees display errors to site visitors, not the log warning. You only meet log errors to a potentially public file after display has been turned off, which makes it the warning of someone who followed the careful recipe. Setting display to <code>null<\/code> also counts as off here, because WordPress then leaves the server\u2019s own display setting alone, so check that the server is not displaying errors itself.<\/p>\n\n\n\n<h3 id=\"aioseo-the-development-environment-exception\" class=\"wp-block-heading\">The Development Environment Exception<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">One setting changes the display grade. When <code>WP_ENVIRONMENT_TYPE<\/code> is set to <code>development<\/code> or <code>local<\/code>, Site Health lowers the display warning to recommended, because printing errors on a development copy is expected. The log warning gets no such exception: its grade depends only on the path. Never set either environment type on a live site to quiet the warning, since plugins read the same value and may change how they behave.<\/p>\n\n\n\n<h2 id=\"aioseo-is-your-potentially-public-file-actually-public-test-it\" class=\"wp-block-heading\">Is Your Potentially Public File Actually Public? Test It<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Because Site Health never checks, the only way to know is to ask for the file the way a stranger would. Open a private browser window, so no login cookie is sent, and request your domain followed by <code>\/wp-content\/debug.log<\/code>. From a terminal, <code>curl -I<\/code> with the same address prints only the response status. If you set a custom path inside <code>public_html<\/code>, request the address that matches it instead.<\/p>\n\n\n\n<h3 id=\"aioseo-what-a-200-403-or-404-means\" class=\"wp-block-heading\">What a 200, 403 or 404 Means<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>200<\/strong>: the file is public. Anyone who requests that address can download it, and so can any automated tool that requests the default path.<\/li>\n\n\n\n<li><strong>403<\/strong>: a rule refuses the request. The file is protected at that address, whatever Site Health says.<\/li>\n\n\n\n<li><strong>404<\/strong>: there is no file at that address right now. Either nothing has been logged yet or the log lives elsewhere. A log created later at the same path would be served, so a 404 is not a reason to leave logging on.<\/li>\n<\/ul>\n\n\n\n<h3 id=\"aioseo-what-a-wordpress-debug-log-gives-away\" class=\"wp-block-heading\">What a WordPress Debug Log Gives Away<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A debug log is written for whoever is fixing the site, so it holds what an attacker would otherwise have to work out. Each PHP warning carries the full server path to the file that raised it, which on shared hosting includes your account username, along with plugin and theme folder names. WordPress also logs failed database queries in full, prefixed with <em>WordPress database error<\/em>, table names included. MITRE\u2019s description of <a href=\"https:\/\/attack.mitre.org\/techniques\/T1592\/002\/\" target=\"_blank\" rel=\"noopener\">gathering software information about a target<\/a> lists accessible data sets as one way that information reaches an attacker. The UK National Cyber Security Centre\u2019s <a href=\"https:\/\/www.ncsc.gov.uk\/guidance\/introduction-logging-security-purposes\" target=\"_blank\" rel=\"noopener\">introduction to logging for security purposes<\/a> asks whether access to logs is limited to the people who need to analyze them. A log in a public folder fails that test by default.<\/p>\n\n\n\n<h2 id=\"aioseo-how-to-fix-a-potentially-public-file-warning-in-order\" class=\"wp-block-heading\">How to Fix a Potentially Public File Warning, in Order<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Work through these in sequence. The first two steps clear the warning, and the third closes the exposure that the warning was about.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Save what you need. Download <code>debug.log<\/code> through cPanel File Manager before you change anything, and read it on your own machine.<\/li>\n\n\n\n<li>Turn debugging off. Set <code>WP_DEBUG<\/code> to <code>false<\/code> in <code>wp-config.php<\/code>. That one change stops WordPress writing the log and turns the result green; the other two constants do nothing while it is off.<\/li>\n\n\n\n<li>Delete the old log. Turning logging off does not remove the file, and it stays downloadable until you delete it. Request its address again afterward and expect a 404.<\/li>\n\n\n\n<li>If you need logging for days, move it. Create a folder outside <code>public_html<\/code>, then set <code>WP_DEBUG_LOG<\/code> to the full path of a file inside it. PHP creates the file, not the folder.<\/li>\n\n\n\n<li>If the log must stay in <code>wp-content<\/code>, deny it. Add a rule to the <code>.htaccess<\/code> file in that folder: a <code>Files<\/code> block naming <code>debug.log<\/code> that contains <code>Require all denied<\/code>. Then request it again and expect a 403. The badge stays critical.<\/li>\n\n\n\n<li>Next time, start with the server\u2019s log. Our guide to the <a href=\"https:\/\/www.ahosting.net\/blog\/wordpress-white-screen-of-death\/\">WordPress white screen of death<\/a> shows where cPanel lists recent PHP errors, which often names the failing file without turning WordPress logging on at all.<\/li>\n<\/ol>\n\n\n\n<h3 id=\"aioseo-grade-your-potentially-public-file-setup\" class=\"wp-block-heading\">Grade Your Potentially Public File Setup<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The same logic as a tool: enter the settings from your <code>wp-config.php<\/code> and it returns the label and grade Site Health will show, whether the log can be downloaded, and the next step.<\/p>\n\n\n\n<style>\n.ahpf-tool{background:#0f172a;border-radius:10px;padding:22px;margin:26px 0;color:#fff;font-size:.95rem}\n.ahpf-tool h3{color:#fff;margin:0 0 6px;font-size:1.15rem}\n.ahpf-tool p.ahpf-sub{color:#eef3ff;margin:0 0 18px;font-size:.88rem}\n.ahpf-f{margin-bottom:14px}\n.ahpf-f label{display:block;color:#eef3ff;font-size:.8rem;margin-bottom:5px}\n.ahpf-f select{width:100%;padding:8px;border:1px solid #334155;border-radius:6px;background:#1e293b;color:#fff;font-size:.9rem;box-sizing:border-box}\n.ahpf-btn{background:#2563eb;color:#fff;border:0;border-radius:6px;padding:10px 20px;font-size:.92rem;cursor:pointer;text-decoration:none;display:inline-block}\n.ahpf-out{margin-top:18px;padding:16px;background:#1e293b;border-left:4px solid #2563eb;border-radius:6px;display:none}\n.ahpf-out.ahpf-on{display:block}\n.ahpf-num{font-size:1.15rem;font-weight:700;color:#60a5fa;display:block;margin-bottom:8px}\n.ahpf-out p{margin:0 0 10px;color:#fff}\n.ahpf-out p strong{color:#93c5fd}\n.ahpf-note{color:#94a3b8;font-size:.78rem;margin-top:12px}\n<\/style>\n<div class=\"ahpf-tool\" data-ahpf=\"grader\">\n  <h3>Potentially Public File Grader<\/h3>\n  <p class=\"ahpf-sub\">Copy the debug settings from your wp-config.php. The answer is the label and grade Site Health will show, whether a visitor can actually download the log, and what to do next.<\/p>\n  <div class=\"ahpf-f\">\n    <label for=\"ahpf-debug\">WP_DEBUG<\/label>\n    <select id=\"ahpf-debug\">\n      <option value=\"on\" selected>true<\/option>\n      <option value=\"off\">false, or not in the file<\/option>\n    <\/select>\n  <\/div>\n  <div class=\"ahpf-f\">\n    <label for=\"ahpf-log\">WP_DEBUG_LOG<\/label>\n    <select id=\"ahpf-log\">\n      <option value=\"true\" selected>true (wp-content\/debug.log)<\/option>\n      <option value=\"inside\">A path inside the WordPress folder<\/option>\n      <option value=\"served\">A path elsewhere in public_html or another served folder<\/option>\n      <option value=\"outside\">A path outside every served folder<\/option>\n      <option value=\"off\">false, or not in the file<\/option>\n    <\/select>\n  <\/div>\n  <div class=\"ahpf-f\">\n    <label for=\"ahpf-display\">WP_DEBUG_DISPLAY<\/label>\n    <select id=\"ahpf-display\">\n      <option value=\"on\" selected>Not in the file, or true<\/option>\n      <option value=\"off\">false or null<\/option>\n    <\/select>\n  <\/div>\n  <div class=\"ahpf-f\">\n    <label for=\"ahpf-env\">WP_ENVIRONMENT_TYPE<\/label>\n    <select id=\"ahpf-env\">\n      <option value=\"live\" selected>Not set, production or staging<\/option>\n      <option value=\"dev\">development or local<\/option>\n    <\/select>\n  <\/div>\n  <button class=\"ahpf-btn wp-element-button\" id=\"ahpf-go\" type=\"button\">Grade it<\/button>\n  <div class=\"ahpf-out\" id=\"ahpf-out\">\n    <span class=\"ahpf-num\" id=\"ahpf-num\">&#8212;<\/span>\n    <p><strong>Grade:<\/strong> <span id=\"ahpf-grade\"><\/span><\/p>\n    <p><strong>Can a visitor download it?<\/strong> <span id=\"ahpf-reach\"><\/span><\/p>\n    <p><strong>Do this next:<\/strong> <span id=\"ahpf-next\"><\/span><\/p>\n    <p class=\"ahpf-note\">Read from the WordPress 7.1.2 source. It cannot see your server, so confirm the download answer by requesting the file yourself.<\/p>\n  <\/div>\n<\/div>\n<script>\n(function(){\n  document.addEventListener('DOMContentLoaded', function(){\n    var tool = document.querySelector('[data-ahpf]');\n    if (!tool) { return; }\n    var mode = tool.getAttribute('data-ahpf');\n    if (mode !== 'grader') { return; }\n    var go = document.getElementById('ahpf-go');\n    if (!go) { return; }\n    var out = document.getElementById('ahpf-out');\n    if (!out) { return; }\n    var num = document.getElementById('ahpf-num');\n    if (!num) { return; }\n    var grade = document.getElementById('ahpf-grade');\n    if (!grade) { return; }\n    var reach = document.getElementById('ahpf-reach');\n    if (!reach) { return; }\n    var next = document.getElementById('ahpf-next');\n    if (!next) { return; }\n    var REACH = {};\n    REACH['true'] = 'Yes, at your domain followed by \/wp-content\/debug.log, unless a rule blocks it.';\n    REACH['inside'] = 'Probably, at the matching address, unless a rule blocks it.';\n    REACH['served'] = 'Yes. Anyone who requests the matching address can download it.';\n    REACH['outside'] = 'No. No address on the web points to that folder.';\n    REACH['off'] = 'WordPress writes no debug log. An old debug.log can still be on disk.';\n    var NEXT = {};\n    NEXT['good'] = 'Request your domain followed by \/wp-content\/debug.log. If an old log downloads, save what you need and delete it.';\n    NEXT['display'] = 'Set WP_DEBUG_DISPLAY to false now, because visitors can see errors in your pages. Then run this again.';\n    NEXT['devdisplay'] = 'Fine on a development copy. Never copy these settings to the live site.';\n    NEXT['crit'] = 'Read what you need, then set WP_DEBUG to false and delete the old log. If you need logging for days, move it outside public_html.';\n    NEXT['served'] = 'Move the log now. A recommended grade here hides a file anyone can download. Use a folder outside every served folder.';\n    NEXT['rec'] = 'This is the safe way to keep logging. Turn WP_DEBUG off when you are done; nothing else turns the result green.';\n    go.addEventListener('click', function(){\n      var db = document.getElementById('ahpf-debug');\n      if (!db) { return; }\n      var lg = document.getElementById('ahpf-log');\n      if (!lg) { return; }\n      var ds = document.getElementById('ahpf-display');\n      if (!ds) { return; }\n      var ev = document.getElementById('ahpf-env');\n      if (!ev) { return; }\n      var label = 'Your site is not set to output debug information';\n      var g = 'Good';\n      var k = 'good';\n      var r = REACH['off'];\n      if (db.value === 'on') {\n        if (lg.value !== 'off') {\n          label = 'Your site is set to log errors to a potentially public file';\n          r = REACH[lg.value];\n          g = 'Recommended';\n          k = 'rec';\n          if (lg.value === 'true') { g = 'Critical'; k = 'crit'; }\n          if (lg.value === 'inside') { g = 'Critical'; k = 'crit'; }\n          if (lg.value === 'served') { k = 'served'; }\n        }\n        if (ds.value === 'on') {\n          label = 'Your site is set to display errors to site visitors';\n          g = 'Critical';\n          k = 'display';\n          if (ev.value === 'dev') { g = 'Recommended'; k = 'devdisplay'; }\n        }\n      }\n      num.innerHTML = label;\n      grade.innerHTML = g;\n      reach.innerHTML = r;\n      next.innerHTML = NEXT[k];\n      out.className = 'ahpf-out ahpf-on';\n    });\n  });\n})();\n<\/script>\n\n\n\n<h2 id=\"aioseo-potentially-public-file-warnings-on-ahosting-servers\" class=\"wp-block-heading\">Potentially Public File Warnings on AHosting Servers<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">On our shared servers, PHP runs as your own cPanel user, inside CloudLinux CageFS. Our post on <a href=\"https:\/\/www.ahosting.net\/blog\/wordpress-hosting-security-2026-server-level-protection\/\">server-level WordPress security<\/a> explains what that isolation does. For a debug log it means two things. WordPress can write to any folder in your home folder without a permissions change, and a folder outside <code>public_html<\/code> has no address on the web. Your home folder is <code>\/home\/<\/code> followed by your cPanel username, so a path such as <code>\/home\/username\/wp-logs\/debug.log<\/code> is the one to use. Avoid folders that serve another domain on the account.<\/p>\n\n\n\n<h3 id=\"aioseo-where-to-put-debug-log-on-ahosting\" class=\"wp-block-heading\">Where to Put debug.log on AHosting<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The handbook\u2019s own example path is <code>\/tmp<\/code>. That works here, but inside CageFS your <code>\/tmp<\/code> is a private folder in your own account that counts against both your disk and inode quota, and a named folder is easier to find later.<\/p>\n\n\n\n<figure class=\"wp-block-table ah-ladder\"><table><thead><tr><th>Where the log lives<\/th><th>Site Health grade<\/th><th>Can a visitor download it?<\/th><th>Verdict<\/th><\/tr><\/thead><tbody><tr><td>wp-content\/debug.log (WP_DEBUG_LOG true)<\/td><td>Critical<\/td><td>Yes, unless a rule blocks it<\/td><td>Only while you are reading it<\/td><\/tr><tr><td>wp-content\/debug.log with a deny rule<\/td><td>Critical<\/td><td>No, if a test returns 403<\/td><td>Acceptable for a short session<\/td><\/tr><tr><td>Elsewhere in public_html<\/td><td>Critical or recommended, by where WordPress is installed<\/td><td>Yes<\/td><td>Never<\/td><\/tr><tr><td>\/tmp (the handbook example)<\/td><td>Recommended<\/td><td>No<\/td><td>Works; counts against disk and inode quota<\/td><\/tr><tr><td>\/home\/username\/wp-logs\/debug.log<\/td><td>Recommended<\/td><td>No<\/td><td>Best place for a log you need for days<\/td><\/tr><tr><td>Logging off (WP_DEBUG false)<\/td><td>Good<\/td><td>Only an old file, until you delete it<\/td><td>The only green result<\/td><\/tr><\/tbody><\/table><figcaption class=\"wp-element-caption\">Where to put debug.log on AHosting \u2014 each location\u2019s Site Health grade, whether a visitor can download it, and our verdict.<\/figcaption><\/figure>\n\n\n\n<h3 id=\"aioseo-a-log-left-running-never-stops-growing\" class=\"wp-block-heading\">A Log Left Running Never Stops Growing<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress never rotates or trims <code>debug.log<\/code>. Every warning and notice adds a line, so a log left running grows against your disk quota and adds a steady stream of small writes; our guide to <a href=\"https:\/\/www.ahosting.net\/blog\/disk-io-throttling-shared-hosting\/\">disk I\/O throttling on shared hosting<\/a> covers why those add up. That is a second reason to treat logging as a session with an end, not a setting.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Everything in this guide works the same way on our <a href=\"https:\/\/www.ahosting.net\/wordpress-hosting.html\">WordPress hosting plans<\/a> and <a href=\"https:\/\/www.ahosting.net\/web-hosting.html\">standard web hosting plans<\/a>. If the log keeps filling with the same error and you cannot tell which plugin writes it, open a ticket with the first lines of the log and we will look at it with you. For a separate staging copy where errors can be displayed safely, <a href=\"https:\/\/www.ahosting.net\/vps-hosting.html\">a VPS with full root access<\/a> lets you set the PHP logging setup for the whole server yourself. The warning alone is not a reason to move.<\/p>\n\n\n\n<h2 id=\"aioseo-a-practical-checklist-for-the-potentially-public-file-warning\" class=\"wp-block-heading\">A Practical Checklist for the Potentially Public File Warning<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Note which label Site Health shows: the log warning or the display warning.<\/li>\n\n\n\n<li>Request <code>\/wp-content\/debug.log<\/code> in a private window and note the status.<\/li>\n\n\n\n<li>Download the log before changing anything if you still need it.<\/li>\n\n\n\n<li>Set <code>WP_DEBUG<\/code> to <code>false<\/code> as soon as the debugging is finished.<\/li>\n\n\n\n<li>Delete the old <code>debug.log<\/code>, then request it again and expect a 404.<\/li>\n\n\n\n<li>For logging over several days, use a full path outside <code>public_html<\/code>.<\/li>\n\n\n\n<li>Create the folder first, because PHP creates the log file but not its folder.<\/li>\n\n\n\n<li>Never leave <code>WP_DEBUG_DISPLAY<\/code> on for a live site.<\/li>\n\n\n\n<li>Treat a recommended grade as a path check, not proof that the file is private.<\/li>\n\n\n\n<li>Check the cPanel error log first next time, before switching WordPress logging on.<\/li>\n<\/ul>\n\n\n\n<h2 id=\"faq-log-errors-to-a-potentially-public-file\" class=\"wp-block-heading\">Frequently Asked Questions: Log Errors to a Potentially Public File<\/h2>\n\n\n\n<h3 id=\"faq-why-does-site-health-still-say-potentially-public-file-after-i-moved-debug-log\" class=\"wp-block-heading\">Why does Site Health still say potentially public file after I moved debug.log?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In practice, the check never looks at the file. Site Health shows the label whenever WP_DEBUG and WP_DEBUG_LOG are both on. Moving the log out of the WordPress folder only changes the grade from critical to recommended, because the grade depends on whether the path starts with the WordPress folder. The label clears only when logging is off, so turn WP_DEBUG off once you have what you need.<\/p>\n\n\n\n<h3 id=\"faq-what-does-log-errors-to-a-potentially-public-file-mean-in-wordpress-in-2026\" class=\"wp-block-heading\">What does log errors to a potentially public file mean in WordPress in 2026?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In other words, WP_DEBUG and WP_DEBUG_LOG are both set to true in wp-config.php while error display is off. In WordPress 7.1 Site Health reads those settings and nothing else. It does not check whether the log exists or whether a visitor can download it. The warning is critical when the log sits inside the WordPress folder and recommended when it sits anywhere else.<\/p>\n\n\n\n<h3 id=\"faq-potentially-public-file-vs-display-errors-to-site-visitors-which-warning-is-worse\" class=\"wp-block-heading\">Potentially public file vs display errors to site visitors: which warning is worse?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Specifically, display errors to site visitors is worse, because every visitor sees the errors in the page itself. Both labels come from the same test. WP_DEBUG_DISPLAY defaults to true, so a site that turns on WP_DEBUG without turning display off gets the display label, graded critical. The potentially public file label only appears once display is off, and it describes a file someone has to request by its address, which is the same default address on every site.<\/p>\n\n\n\n<h3 id=\"faq-can-a-potentially-public-file-protected-by-htaccess-still-show-as-critical\" class=\"wp-block-heading\">Can a potentially public file protected by htaccess still show as critical?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Indeed it can. Site Health grades the log by its path alone, and a log in wp-content starts with the WordPress folder, so it is graded critical whether or not a rule blocks it. A deny rule that returns 403 does protect the file. It does not change the grade, and only turning logging off or moving the log changes what Site Health reports.<\/p>\n\n\n\n<h3 id=\"faq-does-turning-off-wp-debug-delete-the-potentially-public-file-in-wp-content\" class=\"wp-block-heading\">Does turning off WP_DEBUG delete the potentially public file in wp-content?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In fact, no. Setting WP_DEBUG to false stops WordPress from writing new entries and turns the Site Health result green, but the debug.log already on disk stays where it is, and the web server keeps serving it. Download it if you still need it, then delete it in File Manager. Request its address once more afterwards; a 404 confirms that it is gone.<\/p>\n\n\n\n<h3 id=\"faq-wp-debug-log-true-vs-a-custom-path-which-one-is-safer-on-a-live-site\" class=\"wp-block-heading\">WP_DEBUG_LOG true vs a custom path: which one is safer on a live site?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Typically a custom path outside the folder your domain serves. Set to true, WP_DEBUG_LOG writes to wp-content\/debug.log, which the web server can deliver to anyone who requests it. Set to a full path in your home folder, it writes somewhere no address points to, and Site Health lowers the grade to recommended. Logging still writes on every error, so turn it off when you are done.<\/p>\n\n\n\n<h3 id=\"faq-how-do-i-set-a-custom-debug-log-path-in-wordpress-7-1-in-2026\" class=\"wp-block-heading\">How do I set a custom debug log path in WordPress 7.1 in 2026?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">First and foremost, create the folder, because PHP creates the log file but not the folder that holds it. Then set WP_DEBUG_LOG to the full path in wp-config.php, above the line that says to stop editing, for example \/home\/ followed by your cPanel username and \/wp-logs\/debug.log. Trigger a page load, confirm the file appears, and check that Site Health now grades the warning as recommended.<\/p>\n\n\n\n<h3 id=\"faq-where-should-i-put-debug-log-on-ahosting-shared-hosting-in-2026\" class=\"wp-block-heading\">Where should I put debug.log on AHosting shared hosting in 2026?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Above all, outside public_html, in a folder of its own in your home folder. On our servers PHP runs as your own cPanel user inside CageFS, so WordPress can write to a folder there with no permission changes, and no address on the web points to it. Avoid other folders a domain on the account serves from, and turn logging off when the debugging is finished.<\/p>\n\n\n\n<h3 id=\"faq-can-ahosting-support-help-me-read-the-log-behind-a-potentially-public-file-warning\" class=\"wp-block-heading\">Can AHosting support help me read the log behind a potentially public file warning?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Notably, the warning itself needs no ticket: turning WP_DEBUG off clears it, and deleting the old file closes the exposure. If the log keeps filling with the same error and you cannot tell which plugin writes it, open a ticket with the first lines of the log and we will look at it with you.<\/p>\n\n\n\n<h3 id=\"faq-do-i-need-an-ahosting-vps-to-debug-wordpress-with-errors-displayed-in-2026\" class=\"wp-block-heading\">Do I need an AHosting VPS to debug WordPress with errors displayed in 2026?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Fortunately not for this warning. Logging to a file outside public_html works on a shared plan and keeps errors away from visitors. A VPS makes sense when you want a separate staging copy where errors can be displayed safely, with the environment type set to development, or when you want to choose the PHP logging setup for the whole server yourself.<\/p>\n\n\n\n<script>\n(function(){\n  document.addEventListener('DOMContentLoaded', function(){\n    var allH3s = document.querySelectorAll('h3.wp-block-heading');\n    var inFaq = false;\n    for (var i = 0; i < allH3s.length; i++) {\n      var h3 = allH3s[i];\n      var prev = h3.previousElementSibling;\n      if (prev) {\n        if (prev.tagName === 'H2') {\n          var prevId = prev.getAttribute('id');\n          if (prevId) {\n            if (prevId.indexOf('faq-') === 0) {\n              inFaq = true;\n            } else {\n              inFaq = false;\n            }\n          }\n        }\n      }\n      if (inFaq) {\n        initToggle(h3);\n      }\n    }\n    function initToggle(h3) {\n      var answer = h3.nextElementSibling;\n      if (!answer) { return; }\n      if (answer.tagName !== 'P') { return; }\n      answer.style.display = 'none';\n      h3.style.cursor = 'pointer';\n      h3.setAttribute('tabindex', '0');\n      h3.setAttribute('aria-expanded', 'false');\n      h3.addEventListener('click', function(){\n        toggleOne(h3, answer);\n      });\n      h3.addEventListener('keydown', function(ev){\n        if (ev.key === 'Enter') { toggleOne(h3, answer); }\n        if (ev.key === ' ') { ev.preventDefault(); toggleOne(h3, answer); }\n      });\n    }\n    function toggleOne(h3, answer) {\n      var open = h3.getAttribute('aria-expanded') === 'true';\n      if (open) {\n        answer.style.display = 'none';\n        h3.setAttribute('aria-expanded', 'false');\n      } else {\n        answer.style.display = 'block';\n        h3.setAttribute('aria-expanded', 'true');\n      }\n    }\n  });\n})();\n<\/script>\n","protected":false},"excerpt":{"rendered":"<p>TL;DR Your site is set to log errors to a potentially public file means two settings in wp-config.php, WP_DEBUG and WP_DEBUG_LOG, are both on while error display is off. Site Health never checked whether the log can be downloaded. The grade depends only on whether the log&#8217;s path sits inside your WordPress folder, so moving [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1405,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[8],"tags":[66,171,306,267,110,276,113,138,117,239],"class_list":["post-1404","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-wordpress","tag-cpanel","tag-cpanel-error-log","tag-potentially-public-file","tag-server-logs","tag-shared-hosting","tag-site-health","tag-wordpress-errors","tag-wordpress-security","tag-wordpress-troubleshooting","tag-wp-config"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.3 - aioseo.com -->\n\t<meta name=\"description\" content=\"Potentially public file means debug logging is on, not that WordPress found your log online. See why moving it fails and how to fix it safely.\" \/>\n\t<meta name=\"robots\" content=\"max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n\t<meta name=\"author\" content=\"Matt Chrust\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/\" \/>\n\t\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.3\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"AHosting Blog | WordPress Hosting Tips &amp; Guides\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Log Errors to a Potentially Public File: Fix It | AHosting\" \/>\n\t\t<meta property=\"og:description\" content=\"Potentially public file means debug logging is on, not that WordPress found your log online. See why moving it fails and how to fix it safely.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.ahosting.net\/blog\/wp-content\/uploads\/2026\/10\/log-errors-to-a-potentially-public-file-ahosting.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.ahosting.net\/blog\/wp-content\/uploads\/2026\/10\/log-errors-to-a-potentially-public-file-ahosting.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t\t<meta property=\"og:image:height\" content=\"675\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-10-07T13:20:13+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-10-07T14:33:20+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@ahostingdotnet\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Log Errors to a Potentially Public File: Fix It | AHosting\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Potentially public file means debug logging is on, not that WordPress found your log online. See why moving it fails and how to fix it safely.\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@ahostingdotnet\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.ahosting.net\/blog\/wp-content\/uploads\/2026\/10\/log-errors-to-a-potentially-public-file-ahosting.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/log-errors-to-a-potentially-public-file\\\/#article\",\"name\":\"Log Errors to a Potentially Public File: Fix It | AHosting\",\"headline\":\"Log Errors to a Potentially Public File? What Site Health Checks\",\"author\":{\"@type\":\"Person\",\"name\":\"Matt Chrust\",\"url\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/author\\\/matt-chrust\\\/\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/log-errors-to-a-potentially-public-file-ahosting.jpg\",\"width\":1200,\"height\":675,\"caption\":\"The potentially public file warning grades a debug log by its path, not by whether anyone can download it; turn logging off, then delete the file. By Matt Chrust, Director of Business Development, AHosting.\"},\"datePublished\":\"2026-10-07T13:20:13+00:00\",\"dateModified\":\"2026-10-07T14:33:20+00:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/log-errors-to-a-potentially-public-file\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/log-errors-to-a-potentially-public-file\\\/#webpage\"},\"articleSection\":\"WordPress, cPanel, cpanel error log, potentially public file, server logs, Shared Hosting, Site Health, WordPress errors, wordpress security, WordPress troubleshooting, wp-config\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/log-errors-to-a-potentially-public-file\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/category\\\/wordpress\\\/#listItem\",\"name\":\"WordPress\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/category\\\/wordpress\\\/#listItem\",\"position\":2,\"name\":\"WordPress\",\"item\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/category\\\/wordpress\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/log-errors-to-a-potentially-public-file\\\/#listItem\",\"name\":\"Log Errors to a Potentially Public File? What Site Health Checks\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/log-errors-to-a-potentially-public-file\\\/#listItem\",\"position\":3,\"name\":\"Log Errors to a Potentially Public File? What Site Health Checks\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/category\\\/wordpress\\\/#listItem\",\"name\":\"WordPress\"},\"item\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/log-errors-to-a-potentially-public-file\\\/\"}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/#organization\",\"name\":\"AHosting\",\"description\":\"WordPress Hosting Tips & Guides\",\"url\":\"https:\\\/\\\/www.ahosting.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.ahosting.net\\\/assets\\\/img\\\/ahosting-logo.svg\",\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/log-errors-to-a-potentially-public-file\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/log-errors-to-a-potentially-public-file\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/ahostingdotnet\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/author\\\/matt-chrust\\\/#author\",\"url\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/author\\\/matt-chrust\\\/\",\"name\":\"Matt Chrust\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/log-errors-to-a-potentially-public-file\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/795895edac1c44589f6c7f5e6bb79df405fbbaac15817bdd387ec57da61731ec?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Matt Chrust\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/log-errors-to-a-potentially-public-file\\\/#webpage\",\"url\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/log-errors-to-a-potentially-public-file\\\/\",\"name\":\"Log Errors to a Potentially Public File: Fix It | AHosting\",\"description\":\"Potentially public file means debug logging is on, not that WordPress found your log online. See why moving it fails and how to fix it safely.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/log-errors-to-a-potentially-public-file\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/author\\\/matt-chrust\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/author\\\/matt-chrust\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/log-errors-to-a-potentially-public-file-ahosting.jpg\",\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/log-errors-to-a-potentially-public-file\\\/#mainImage\",\"width\":1200,\"height\":675,\"caption\":\"The potentially public file warning grades a debug log by its path, not by whether anyone can download it; turn logging off, then delete the file. By Matt Chrust, Director of Business Development, AHosting.\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/blog\\\/log-errors-to-a-potentially-public-file\\\/#mainImage\"},\"datePublished\":\"2026-10-07T13:20:13+00:00\",\"dateModified\":\"2026-10-07T14:33:20+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/#website\",\"url\":\"https:\\\/\\\/www.ahosting.net\\\/\",\"name\":\"AHosting\",\"description\":\"WordPress Hosting Tips & Guides\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.ahosting.net\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Log Errors to a Potentially Public File: Fix It | AHosting","description":"Potentially public file means debug logging is on, not that WordPress found your log online. See why moving it fails and how to fix it safely.","canonical_url":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/","robots":"max-snippet:-1, max-image-preview:large, max-video-preview:-1","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/#article","name":"Log Errors to a Potentially Public File: Fix It | AHosting","headline":"Log Errors to a Potentially Public File? What Site Health Checks","author":{"@type":"Person","name":"Matt Chrust","url":"https:\/\/www.ahosting.net\/blog\/author\/matt-chrust\/"},"publisher":{"@id":"https:\/\/www.ahosting.net\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.ahosting.net\/blog\/wp-content\/uploads\/2026\/10\/log-errors-to-a-potentially-public-file-ahosting.jpg","width":1200,"height":675,"caption":"The potentially public file warning grades a debug log by its path, not by whether anyone can download it; turn logging off, then delete the file. By Matt Chrust, Director of Business Development, AHosting."},"datePublished":"2026-10-07T13:20:13+00:00","dateModified":"2026-10-07T14:33:20+00:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/#webpage"},"isPartOf":{"@id":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/#webpage"},"articleSection":"WordPress, cPanel, cpanel error log, potentially public file, server logs, Shared Hosting, Site Health, WordPress errors, wordpress security, WordPress troubleshooting, wp-config"},{"@type":"BreadcrumbList","@id":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.ahosting.net\/blog\/#listItem","position":1,"name":"Home","item":"https:\/\/www.ahosting.net\/blog\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.ahosting.net\/blog\/category\/wordpress\/#listItem","name":"WordPress"}},{"@type":"ListItem","@id":"https:\/\/www.ahosting.net\/blog\/category\/wordpress\/#listItem","position":2,"name":"WordPress","item":"https:\/\/www.ahosting.net\/blog\/category\/wordpress\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/#listItem","name":"Log Errors to a Potentially Public File? What Site Health Checks"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.ahosting.net\/blog\/#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/#listItem","position":3,"name":"Log Errors to a Potentially Public File? What Site Health Checks","previousItem":{"@type":"ListItem","@id":"https:\/\/www.ahosting.net\/blog\/category\/wordpress\/#listItem","name":"WordPress"},"item":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/"}]},{"@type":"Organization","@id":"https:\/\/www.ahosting.net\/#organization","name":"AHosting","description":"WordPress Hosting Tips & Guides","url":"https:\/\/www.ahosting.net\/","logo":{"@type":"ImageObject","url":"https:\/\/www.ahosting.net\/assets\/img\/ahosting-logo.svg","@id":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/#organizationLogo"},"image":{"@id":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/#organizationLogo"},"sameAs":["https:\/\/x.com\/ahostingdotnet"]},{"@type":"Person","@id":"https:\/\/www.ahosting.net\/blog\/author\/matt-chrust\/#author","url":"https:\/\/www.ahosting.net\/blog\/author\/matt-chrust\/","name":"Matt Chrust","image":{"@type":"ImageObject","@id":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/795895edac1c44589f6c7f5e6bb79df405fbbaac15817bdd387ec57da61731ec?s=96&d=mm&r=g","width":96,"height":96,"caption":"Matt Chrust"}},{"@type":"WebPage","@id":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/#webpage","url":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/","name":"Log Errors to a Potentially Public File: Fix It | AHosting","description":"Potentially public file means debug logging is on, not that WordPress found your log online. See why moving it fails and how to fix it safely.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.ahosting.net\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/#breadcrumblist"},"author":{"@id":"https:\/\/www.ahosting.net\/blog\/author\/matt-chrust\/#author"},"creator":{"@id":"https:\/\/www.ahosting.net\/blog\/author\/matt-chrust\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.ahosting.net\/blog\/wp-content\/uploads\/2026\/10\/log-errors-to-a-potentially-public-file-ahosting.jpg","@id":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/#mainImage","width":1200,"height":675,"caption":"The potentially public file warning grades a debug log by its path, not by whether anyone can download it; turn logging off, then delete the file. By Matt Chrust, Director of Business Development, AHosting."},"primaryImageOfPage":{"@id":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/#mainImage"},"datePublished":"2026-10-07T13:20:13+00:00","dateModified":"2026-10-07T14:33:20+00:00"},{"@type":"WebSite","@id":"https:\/\/www.ahosting.net\/#website","url":"https:\/\/www.ahosting.net\/","name":"AHosting","description":"WordPress Hosting Tips & Guides","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.ahosting.net\/#organization"}}]},"og:locale":"en_US","og:site_name":"AHosting Blog | WordPress Hosting Tips &amp; Guides","og:type":"article","og:title":"Log Errors to a Potentially Public File: Fix It | AHosting","og:description":"Potentially public file means debug logging is on, not that WordPress found your log online. See why moving it fails and how to fix it safely.","og:url":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/","og:image":"https:\/\/www.ahosting.net\/blog\/wp-content\/uploads\/2026\/10\/log-errors-to-a-potentially-public-file-ahosting.jpg","og:image:secure_url":"https:\/\/www.ahosting.net\/blog\/wp-content\/uploads\/2026\/10\/log-errors-to-a-potentially-public-file-ahosting.jpg","og:image:width":1200,"og:image:height":675,"article:published_time":"2026-10-07T13:20:13+00:00","article:modified_time":"2026-10-07T14:33:20+00:00","twitter:card":"summary_large_image","twitter:site":"@ahostingdotnet","twitter:title":"Log Errors to a Potentially Public File: Fix It | AHosting","twitter:description":"Potentially public file means debug logging is on, not that WordPress found your log online. See why moving it fails and how to fix it safely.","twitter:creator":"@ahostingdotnet","twitter:image":"https:\/\/www.ahosting.net\/blog\/wp-content\/uploads\/2026\/10\/log-errors-to-a-potentially-public-file-ahosting.jpg"},"aioseo_meta_data":{"post_id":"1404","title":"Log Errors to a Potentially Public File: Fix It | AHosting","description":"Potentially public file means debug logging is on, not that WordPress found your log online. See why moving it fails and how to fix it safely.","keywords":null,"keyphrases":{"focus":{"keyphrase":"potentially public file","score":0,"analysis":[]},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-10-07 13:16:52","updated":"2026-10-07 14:33:31","seo_analyzer_scan_date":null,"focus_keyword":"potentially public file","additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.ahosting.net\/blog\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.ahosting.net\/blog\/category\/wordpress\/\" title=\"WordPress\">WordPress<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tLog Errors to a Potentially Public File? What Site Health Checks\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.ahosting.net\/blog\/"},{"label":"WordPress","link":"https:\/\/www.ahosting.net\/blog\/category\/wordpress\/"},{"label":"Log Errors to a Potentially Public File? What Site Health Checks","link":"https:\/\/www.ahosting.net\/blog\/log-errors-to-a-potentially-public-file\/"}],"_links":{"self":[{"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/posts\/1404","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/comments?post=1404"}],"version-history":[{"count":2,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/posts\/1404\/revisions"}],"predecessor-version":[{"id":1410,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/posts\/1404\/revisions\/1410"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/media\/1405"}],"wp:attachment":[{"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/media?parent=1404"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/categories?post=1404"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ahosting.net\/blog\/wp-json\/wp\/v2\/tags?post=1404"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}