wppaste
WordPress

wp_die( string|WP_Error|int $message = '', string|int $title = '', string|array|int $args = array() ): void

Since
2.0.4, 4.1.0, 5.1.0, 5.3.0, 5.5.0
Source
wp-includes/functions.php:3820

Halts execution and renders an HTML error screen built from $message and $title, exiting PHP by default. Passing an integer for $title or $args sets the HTTP response code as a shorthand for array('response' => code). Ajax, JSON, JSONP REST, XML-RPC and feed requests are each detected automatically and routed through a different filterable output handler, so the same call can produce JSON instead of an HTML page depending on context.

Kills WordPress execution and displays HTML page with an error message.

Description

This function complements the die() PHP function. The difference is that HTML will be displayed to the user. It is recommended to use this function only when the execution should not continue any further. It is not recommended to call this function very often, and try to handle as many errors as possible silently or more gracefully.

As a shorthand, the desired HTTP response code may be passed as an integer to the $title parameter (the default title would apply) or the $args parameter.

Compatibility

WordPress
since 5.5.0
PHP
7.4–8.6-dev
  • 6.7.7
  • 6.8.8
  • 6.9.7
  • 7.0.4
  • 7.1.0

Present in every tracked release (6.7.7 to 7.1.0), and compiles on PHP 7.4 through 8.6-dev.

Parameters

$messagestring|WP_Error|intoptional
Error message. If this is a WP_Error object, and not an Ajax or XML-RPC request, the error's messages are used.
An integer is echoed as the entire response body by legacy Ajax handlers, which use -1 for a failed nonce or capability check, 0 for failure, and 1 for success. Default empty string.Default: ''
$titlestring|intoptional
Error title. If $message is a WP_Error object, error data with the key 'title' may be used to specify the title.
If $title is an integer, then it is treated as the response code.
Default empty string.Default: ''
$argsstring|array|intoptional
Arguments to control behavior. If $args is an integer, then it is treated as the response code. Default empty array.Default: array()
  • $responseintdefault: 200 for Ajax requests, 500 otherwise

    The HTTP response code.
  • $link_urlstringdefault: empty string

    A URL to include a link to. Only works in combination with $link_text.
  • $link_textstringdefault: empty string

    A label for the link to include. Only works in combination with $link_url.
  • $back_linkbooldefault: false

    Whether to include a link to go back.
  • $text_directionstringdefault: is the value of is_rtl()

    The text direction. This is only useful internally, when WordPress is still loading and the site's locale is not set up yet. Accepts 'rtl' and 'ltr'.
  • $charsetstringdefault: 'utf-8'

    Character set of the HTML output.
  • $codestringdefault: is 'wp_die', or the main error code if $message is a WP_Error

    Error code to use.
  • $exitbooldefault: true

    Whether to exit the process after completion.

Return value

void
Never returns if $args['exit'] is true (the default), otherwise returns void.

Code examples

Every example is editable and runs in a real WordPress booted in your browser by WordPress Playground. Press Run, then edit the code: clicking away re-runs it. Nothing is sent anywhere until you do.

Die with a WP_Error and a 404 response code when a post is missing

Look up a post that does not exist in the baseline fixtures and stop the request with a formatted error screen.

$post_id = 999999;
$post    = get_post( $post_id );

if ( ! $post ) {
	$error = new WP_Error(
		'invalid_post',
		sprintf( 'No post exists with ID %d.', $post_id ),
		array( 'title' => 'Post Not Found' )
	);

	wp_die( $error, '', array( 'response' => 404, 'back_link' => true ) );
}

echo esc_html( $post->post_title );

Because $args['exit'] defaults to true, nothing written after this call in the current request will run.

Use the integer shorthand for a 403 response code in a capability check

Guard a settings page with current_user_can() and pass the HTTP status directly as $title.

$can_manage = current_user_can( 'manage_options' );

if ( ! $can_manage ) {
	wp_die( 'You do not have permission to view this settings page.', 403 );
}

$price = get_post_meta( 2, 'price', true );

echo esc_html( 'Access granted. Stored price meta for post 2 is: ' . $price );

The logged in administrator in the sandbox passes the check, so this prints the meta value instead of dying; try it with a lower-privileged user to see the 403 screen.

Common problems and fixes · 4

Why does the rest of my code stop running after wp_die()?

The $args['exit'] sub-parameter defaults to true, and wp_die() terminates the process once it finishes outputting rather than returning control to your script.

Why isn't my WP_Error message showing up when I pass it to wp_die()?

WP_Error messages are only read when the request is neither an Ajax nor an XML-RPC request. During wp_doing_ajax() or an XMLRPC_REQUEST, a different filterable handler (_ajax_wp_die_handler or _xmlrpc_wp_die_handler) formats the output instead of reading the error's messages.

Why did calling wp_die() output JSON instead of the styled HTML error page I expected?

wp_die() checks wp_doing_ajax(), wp_is_json_request(), the combination of wp_is_serving_rest_request() and wp_is_jsonp_request(), the XMLRPC_REQUEST constant, and wp_is_xml_request() plus feed checks on the global $wp_query, and routes to a different hook (wp_die_ajax_handler, wp_die_json_handler, wp_die_jsonp_handler, wp_die_xmlrpc_handler, wp_die_xml_handler, or the default wp_die_handler) depending on which one matches first.

Why does the response code I passed get overridden with 200 or 500?

If $args does not include a 'response' key, the default is 200 for Ajax requests and 500 for everything else, per the $args sub-parameters. Passing the code correctly means either using the integer shorthand for $title/$args or setting 'response' explicitly inside the $args array.

Alternatives and related functions

WP_Error
When you need to build a structured error with a code, message, and extra data (like a 'title') before deciding whether to hand it to wp_die() or handle it another way.
wp_send_json_error
When you are inside an Ajax callback and want a JSON error response without manually branching on wp_doing_ajax().
status_header
When you only need to send an HTTP status code and keep executing PHP afterward, without halting the request or rendering an error message.
WP_Ajax_Response
When building a legacy XML Ajax response, as used internally by admin-ajax handlers, instead of terminating with an HTML or JSON die screen.

Performance profile

How much work a call to wp_die() does, and what it touches: the algorithmic scaling, the Zend instruction count per call across PHP versions, the hooks it hands control to, and the core code that calls it. Measured from the compiled opcodes, not a stopwatch, so every number is identical on any machine running the same PHP version, and every function in core is ranked by cost.

Cost class
Trivial

Touches nothing outside its own arguments.

Scaling
Constant

No loop in the body: the same number of instructions runs whatever you pass in.

Instructions
23–65

Executed per call on PHP 8.5, depending on the branch taken. The body compiles to 97.

Plugin surface
6 hooks

Third-party callbacks on 'wp_die_ajax_handler', 'wp_die_json_handler', 'wp_die_jsonp_handler' run inside this call, and their cost is not bounded by anything here.

Called by
50

50 places in core call this, so the cost is paid more often than your own code shows.

What it touches

  • hookthird-party callbacksapply_filters()called directly

Further down the call graph this can also reach query, option, cache, serialize and transient. Those are the worst case, several calls deep and usually down an error path, not what a normal call pays.

What one call costs · 28 distinct outcomes

One number would be a lie: the work depends on which branch runs. These are every distinct cost wp_die() can have, taken from its control-flow graph on PHP 8.5.

WhenInstructionsCalls it makes
wp_doing_ajax()23–26wp_doing_ajax(), apply_filters(), call_user_func()
!wp_doing_ajax() && wp_is_json_request()26–29wp_doing_ajax(), wp_is_json_request(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && wp_is_serving_rest_request()32–39wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_jsonp_request(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && !wp_is_serving_rest_request() && defined('XMLRPC_REQUEST')33–36wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && !wp_is_serving_rest_request()34–40wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_xml_request(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && wp_is_serving_rest_request() && !wp_is_jsonp_request()37–43wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_jsonp_request(), wp_is_xml_request(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && !wp_is_serving_rest_request() && !wp_is_xml_request() && isset($wp_query) && function_exists() && is_feed()43–48wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_xml_request(), function_exists(), is_feed(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && wp_is_serving_rest_request() && !wp_is_jsonp_request() && !wp_is_xml_request() && isset($wp_query) && function_exists() && is_feed()46–51wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_jsonp_request(), wp_is_xml_request(), function_exists(), is_feed(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && !wp_is_serving_rest_request() && !wp_is_xml_request() && isset($wp_query) && !function_exists()47–52wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_xml_request(), function_exists(), function_exists(), function_exists(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && !wp_is_serving_rest_request() && !wp_is_xml_request() && isset($wp_query) && is_comment_feed()47–52wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_xml_request(), function_exists(), function_exists(), is_comment_feed(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && !wp_is_serving_rest_request() && !wp_is_xml_request() && isset($wp_query)50–56wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_xml_request(), function_exists(), function_exists(), function_exists(), is_trackback(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && !wp_is_serving_rest_request() && !wp_is_xml_request() && isset($wp_query) && !is_comment_feed()50–55wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_xml_request(), function_exists(), function_exists(), is_comment_feed(), function_exists(), apply_filters(), call_user_func()
16 further outcomes, up to 65 instructions
!wp_doing_ajax() && !wp_is_json_request() && !wp_is_serving_rest_request() && !wp_is_xml_request() && isset($wp_query) && !is_feed()50–55wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_xml_request(), function_exists(), is_feed(), function_exists(), function_exists(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && !wp_is_serving_rest_request() && !wp_is_xml_request() && isset($wp_query) && function_exists() && !is_feed() && is_comment_feed()50–55wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_xml_request(), function_exists(), is_feed(), function_exists(), is_comment_feed(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && wp_is_serving_rest_request() && !wp_is_jsonp_request() && !wp_is_xml_request() && isset($wp_query) && !function_exists()50–55wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_jsonp_request(), wp_is_xml_request(), function_exists(), function_exists(), function_exists(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && wp_is_serving_rest_request() && !wp_is_jsonp_request() && !wp_is_xml_request() && isset($wp_query) && is_comment_feed()50–55wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_jsonp_request(), wp_is_xml_request(), function_exists(), function_exists(), is_comment_feed(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && !wp_is_serving_rest_request() && !wp_is_xml_request() && isset($wp_query) && !is_comment_feed()53–59wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_xml_request(), function_exists(), function_exists(), is_comment_feed(), function_exists(), is_trackback(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && !wp_is_serving_rest_request() && !wp_is_xml_request() && isset($wp_query) && !is_feed()53–59wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_xml_request(), function_exists(), is_feed(), function_exists(), function_exists(), is_trackback(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && !wp_is_serving_rest_request() && !wp_is_xml_request() && isset($wp_query) && !is_feed() && !is_comment_feed()53–58wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_xml_request(), function_exists(), is_feed(), function_exists(), is_comment_feed(), function_exists(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && wp_is_serving_rest_request() && !wp_is_jsonp_request() && !wp_is_xml_request() && isset($wp_query)53–59wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_jsonp_request(), wp_is_xml_request(), function_exists(), function_exists(), function_exists(), is_trackback(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && wp_is_serving_rest_request() && !wp_is_jsonp_request() && !wp_is_xml_request() && isset($wp_query) && !is_comment_feed()53–58wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_jsonp_request(), wp_is_xml_request(), function_exists(), function_exists(), is_comment_feed(), function_exists(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && wp_is_serving_rest_request() && !wp_is_jsonp_request() && !wp_is_xml_request() && isset($wp_query) && !is_feed()53–58wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_jsonp_request(), wp_is_xml_request(), function_exists(), is_feed(), function_exists(), function_exists(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && wp_is_serving_rest_request() && !wp_is_jsonp_request() && !wp_is_xml_request() && isset($wp_query) && function_exists() && !is_feed() && is_comment_feed()53–58wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_jsonp_request(), wp_is_xml_request(), function_exists(), is_feed(), function_exists(), is_comment_feed(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && !wp_is_serving_rest_request() && !wp_is_xml_request() && isset($wp_query) && function_exists() && !is_feed() && !is_comment_feed()56–62wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_xml_request(), function_exists(), is_feed(), function_exists(), is_comment_feed(), function_exists(), is_trackback(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && wp_is_serving_rest_request() && !wp_is_jsonp_request() && !wp_is_xml_request() && isset($wp_query) && !is_comment_feed()56–62wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_jsonp_request(), wp_is_xml_request(), function_exists(), function_exists(), is_comment_feed(), function_exists(), is_trackback(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && wp_is_serving_rest_request() && !wp_is_jsonp_request() && !wp_is_xml_request() && isset($wp_query) && !is_feed()56–62wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_jsonp_request(), wp_is_xml_request(), function_exists(), is_feed(), function_exists(), function_exists(), is_trackback(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && wp_is_serving_rest_request() && !wp_is_jsonp_request() && !wp_is_xml_request() && isset($wp_query) && !is_feed() && !is_comment_feed()56–61wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_jsonp_request(), wp_is_xml_request(), function_exists(), is_feed(), function_exists(), is_comment_feed(), function_exists(), apply_filters(), call_user_func()
!wp_doing_ajax() && !wp_is_json_request() && wp_is_serving_rest_request() && !wp_is_jsonp_request() && !wp_is_xml_request() && isset($wp_query) && function_exists() && !is_feed() && !is_comment_feed()59–65wp_doing_ajax(), wp_is_json_request(), wp_is_serving_rest_request(), wp_is_jsonp_request(), wp_is_xml_request(), function_exists(), is_feed(), function_exists(), is_comment_feed(), function_exists(), is_trackback(), apply_filters(), call_user_func()

Across PHP versions

PHPCompiledExecutedBranchesNotes
8.6-dev9723–6516
8.59723–6516
8.49723–6516
8.39723–6516
8.29723–6516
8.19723–65163 fewer instructions than PHP 7.4
7.410023–6816

An instruction is not a fixed amount of time, so a matching count is not necessarily the same speed; what it rules out is a difference in the work itself.

Hooks and filters fired · 6

6 hooks fire while wp_die() runs, in this order:

  1. apply_filters( wp_die_ajax_handler )filterline 3838 (+18 into the body)

    Filters the callback for killing WordPress execution for Ajax requests.

  2. apply_filters( wp_die_json_handler )filterline 3847 (+27 into the body)

    Filters the callback for killing WordPress execution for JSON requests.

  3. apply_filters( wp_die_jsonp_handler )filterline 3856 (+36 into the body)

    Filters the callback for killing WordPress execution for JSONP REST requests.

  4. apply_filters( wp_die_xmlrpc_handler )filterline 3865 (+45 into the body)

    Filters the callback for killing WordPress execution for XML-RPC requests.

  5. apply_filters( wp_die_xml_handler )filterline 3878 (+58 into the body)

    Filters the callback for killing WordPress execution for XML requests.

  6. apply_filters( wp_die_handler )filterline 3887 (+67 into the body)

    Filters the callback for killing WordPress execution for all non-Ajax, non-JSON, non-XML requests.

Uses · 9

Used by · 50

Show all 50

Source code

function wp_die( $message = '', $title = '', $args = array() ) {	global $wp_query; 	if ( is_int( $args ) ) {		$args = array( 'response' => $args );	} elseif ( is_int( $title ) ) {		$args  = array( 'response' => $title );		$title = '';	} 	if ( wp_doing_ajax() ) {		/**		 * Filters the callback for killing WordPress execution for Ajax requests.		 *		 * @since 3.4.0		 *		 * @param callable $callback Callback function name.		 */		$callback = apply_filters( 'wp_die_ajax_handler', '_ajax_wp_die_handler' );	} elseif ( wp_is_json_request() ) {		/**		 * Filters the callback for killing WordPress execution for JSON requests.		 *		 * @since 5.1.0		 *		 * @param callable $callback Callback function name.		 */		$callback = apply_filters( 'wp_die_json_handler', '_json_wp_die_handler' );	} elseif ( wp_is_serving_rest_request() && wp_is_jsonp_request() ) {		/**		 * Filters the callback for killing WordPress execution for JSONP REST requests.		 *		 * @since 5.2.0		 *		 * @param callable $callback Callback function name.		 */		$callback = apply_filters( 'wp_die_jsonp_handler', '_jsonp_wp_die_handler' );	} elseif ( defined( 'XMLRPC_REQUEST' ) && XMLRPC_REQUEST ) {		/**		 * Filters the callback for killing WordPress execution for XML-RPC requests.		 *		 * @since 3.4.0		 *		 * @param callable $callback Callback function name.		 */		$callback = apply_filters( 'wp_die_xmlrpc_handler', '_xmlrpc_wp_die_handler' );	} elseif ( wp_is_xml_request()		|| isset( $wp_query ) &&			( function_exists( 'is_feed' ) && is_feed()			|| function_exists( 'is_comment_feed' ) && is_comment_feed()			|| function_exists( 'is_trackback' ) && is_trackback() ) ) {		/**		 * Filters the callback for killing WordPress execution for XML requests.		 *		 * @since 5.2.0		 *		 * @param callable $callback Callback function name.		 */		$callback = apply_filters( 'wp_die_xml_handler', '_xml_wp_die_handler' );	} else {		/**		 * Filters the callback for killing WordPress execution for all non-Ajax, non-JSON, non-XML requests.		 *		 * @since 3.0.0		 *		 * @param callable $callback Callback function name.		 */		$callback = apply_filters( 'wp_die_handler', '_default_wp_die_handler' );	} 	call_user_func( $callback, $message, $title, $args );}

Changelog

Introduced in 2.0.4. 3 changes between 6.7.7 and 7.1.0.

  1. 6.7.7
  2. 6.8.8
  3. 6.9.7
  4. 7.0.4
  5. 7.1.0

Signature, return type and hooks compared across 5 parsed releases.

7.1.0
Parameter $message retyped from string|WP_Error to string|WP_Error|int.verified against source
7.1.0
Return type changed from never|void to void.verified against source
7.0.4
Return type changed from none to never|void.verified against source
5.5.0
The $text_direction argument has a priority over get_language_attributes() in the default handler.from the docblock
5.3.0
The $charset argument was added.from the docblock
5.1.0
The $link_url, $link_text, and $exit arguments were added.from the docblock
4.1.0
The $title and $args parameters were changed to optionally accept an integer to be used as the response code.from the docblock
2.0.4
Introduced.from the docblock

About this page

Parsed data
Generated from the wordpress-develop 7.1.0 tag, from src/wp-includes/functions.php, and regenerated for each WordPress release so it tracks the code rather than a snapshot of it.
Corrections
Something wrong on this page? Report it and it gets fixed in the next regeneration.