DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
World desk3 min

Can You Rely on PHP’s $_SERVER[‘SCRIPT_URI’]?

PHP does not guarantee that SCRIPT_URI is available. Choose REQUEST_URI for the requested URI, SCRIPT_NAME for the executing script, and validate host and scheme when building absolute URLs.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

No—not portably. PHP does not guarantee that $_SERVER['SCRIPT_URI'] exists: web servers populate $_SERVER, and they may omit entries or add server-specific ones. Use the variable that matches the value you need, and check that optional server variables exist before reading them.

Why SCRIPT_URI is not reliable across servers

PHP’s $_SERVER manual explains that its entries are created by the web server. It explicitly warns: “The entries in this array are created by the web server, therefore there is no guarantee that every web server will provide any of these; servers may omit some, or provide others not listed here.” The manual documents SCRIPT_NAME and REQUEST_URI, but does not list SCRIPT_URI. That omission does not mean no server ever supplies it; it does mean PHP offers no portable guarantee that it will be present.

A 2010 SitePoint Forums discussion reported SCRIPT_URI as NULL on the poster’s local XAMPP setup. That is a useful example of why code can encounter a missing value, not a current compatibility test of XAMPP or a comparison of server stacks. Neither source establishes a support matrix for Apache, nginx, PHP-FPM, CGI, proxies, or hosting providers.

Choose the value that matches what your code needs

What you need Use Important distinction
URI used for the incoming request $_SERVER['REQUEST_URI'] PHP describes this as the URI given to access the page. Confirm it represents the route your application needs.
Path of the executing script $_SERVER['SCRIPT_NAME'] This is the current script path. With URL rewriting, it may differ from the public-facing route.
Indication that PHP received an HTTPS request $_SERVER['HTTPS'] PHP documents it as set to a non-empty value for HTTPS requests; proxy setups may require deployment-specific handling.
A complete absolute URL Build from a scheme, a trusted host, and the required path These are separate pieces. The application’s deployment and host-trust rules determine how to assemble them safely.
SCRIPT_URI, if a particular environment provides it Check for its existence and confirm behavior in that environment It is not among the documented $_SERVER indices and is not guaranteed by PHP’s server-variable contract.

The distinction between REQUEST_URI and SCRIPT_NAME matters most when rewriting is involved: one describes the requested URI, while the other identifies the executing script. The original SitePoint question raised precisely this difference between a public URL and the PHP script handling it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to handle an optional variable

If you have a specific reason to use SCRIPT_URI, treat it as an optional, environment-dependent value rather than a required part of PHP. For example:

$scriptUri = $_SERVER['SCRIPT_URI'] ?? null;

if ($scriptUri !== null) {
    // Use it only if this environment's value matches your needs.
} else {
    // Handle the missing value or use an application-specific alternative.
}

This prevents an absent key from being read as though it were guaranteed. It does not verify that a server-provided value is correct for your purpose, nor does it make the value portable. If your application needs a stable canonical URL—for example, in an email—configure the canonical domain rather than deriving it from an arbitrary request.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Build absolute URLs with an explicit trust model

An absolute URL requires a scheme and a host as well as a path. PHP documents HTTPS as non-empty for HTTPS requests, but reverse proxies and other deployments can affect how the application sees the connection. Handle the scheme according to your actual proxy and application configuration.

Do not assume $_SERVER['SERVER_NAME'] is inherently trustworthy. PHP warns that under some Apache configurations it can reflect a client-supplied hostname, which may be spoofed. A validated request host or an application-configured canonical host is more appropriate when the URL is security-sensitive or must remain stable. The historical forum suggestion to combine HTTP_HOST, REQUEST_URI, and a scheme check should not be treated as a universal security recipe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Practical decision

  • Need the incoming route? Start with REQUEST_URI.
  • Need the path of the PHP file that runs? Use SCRIPT_NAME, allowing for URL rewriting.
  • Need an absolute URL? Determine the path, scheme, and trusted host separately.
  • Need SCRIPT_URI for a particular server? Guard against its absence and verify what that environment supplies.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.