Ffile2fix
Sign in Get started

Fix .htaccess "Invalid command ... perhaps misspelled"

/home/user/public_html/.htaccess: Invalid command 'php_value', perhaps misspelled or defined by a module not included in the server configuration

Apache found a directive in .htaccess that no loaded module provides, so it stops and returns a 500 Internal Server Error. The name in quotes tells you which line: either its module is not enabled, it belongs to a different PHP handler, or the line contains a typo or hidden characters.

Also appears as: .htaccess: Invalid command 'Header', perhaps misspelled or defined by a module not included in the server configuration · .htaccess: Invalid command 'Order', perhaps misspelled or defined by a module not included in the server configuration · .htaccess: Invalid command 'ExpiresActive', perhaps misspelled or defined by a module not included in the server configuration · .htaccess: Invalid command '\xef\xbb\xbfRewriteEngine', perhaps misspelled or defined by a module not included in the server configuration

Common causes

  • php_value or php_flag used while PHP runs as PHP-FPM, CGI or LSAPI instead of mod_php
  • Header, ExpiresActive or RewriteEngine used without mod_headers, mod_expires or mod_rewrite loaded
  • Apache 2.2 style Order, Allow and Deny lines on Apache 2.4 without mod_access_compat
  • A UTF-8 byte order mark (shown as \xef\xbb\xbf) or smart quotes saved by a text editor
  • A typo in the directive name or a directive that is only valid in the main server config
  • Rules copied from an Nginx or LiteSpeed guide that use syntax Apache does not understand

How to fix it

  1. Find the directive named in the log. Open the Apache error log or cPanel Errors page. The quoted name in Invalid command '...' is the exact directive that failed.
  2. Replace php_value under PHP-FPM. Remove php_value and php_flag lines and put the settings in a .user.ini file in the site root, for example memory_limit = 256M. PHP-FPM rereads .user.ini every 300 seconds by default (user_ini.cache_ttl).
  3. Enable the missing module. On Debian/Ubuntu run sudo a2enmod headers expires rewrite and restart Apache. On shared hosting, ask the host or wrap optional blocks in <IfModule mod_headers.c>.
  4. Update Apache 2.2 access rules. Replace Order allow,deny plus Allow from all with Require all granted, and Deny from all with Require all denied.
  5. Remove hidden characters. Re-save .htaccess as UTF-8 without BOM using plain straight quotes. Check with head -c 3 .htaccess | xxd; ef bb bf at the start means a BOM is present.

.htaccess (Apache 2.4) + .user.ini

# .htaccess
<IfModule mod_headers.c>
    Header set X-Content-Type-Options "nosniff"
</IfModule>
<Files ".env">
    Require all denied
</Files>

# .user.ini (instead of php_value under PHP-FPM)
memory_limit = 256M
upload_max_filesize = 64M

How to stop it happening again

  • Use .user.ini for PHP settings so they work under any PHP handler
  • Wrap module-specific blocks in <IfModule> in files you share between servers
  • Edit .htaccess with a code editor set to UTF-8 without BOM
  • Validate .htaccess before uploading it to production

Frequently asked questions

Why does one bad line take the whole site down?

Apache parses .htaccess on every request and treats any unknown directive as a fatal configuration error for that directory, so every request returns 500.

How do I know if my host uses mod_php or PHP-FPM?

Create a phpinfo() page and look at Server API. "Apache 2.0 Handler" means mod_php; "FPM/FastCGI" or "LiteSpeed V8" means php_value will not work in .htaccess.

Do Order/Allow/Deny rules still work on Apache 2.4?

Only if mod_access_compat is loaded, and mixing old and new syntax gives confusing results. Converting to Require is the reliable fix.