News Feed
Jobs Feed
Sections




News Archive
Looking for more information on how to do PHP the right way? Check out PHP: The Right Way

Sara Golemon's Blog:
create_function() is not your friend
May 21, 2007 @ 09:31:00

In response to this previous post from Felix Geisendorfer, Sara Golemon shares a few thoughts on why she thinks it's just the other way around - create_function is not your friend.

In the short post she lists just a few of the issues surrounding the use of the function including that it:

  • is prone to critical abuse by user-supplied code
  • skips opcode cache optimizations
  • encourages not using comments (evil)
  • 100% blind to reflection or PHPDoc style documentation generation

0 comments voice your opinion now!
createfunction eval abuse opcodecache reflection phpdoc createfunction eval abuse opcodecache reflection phpdoc


blog comments powered by Disqus

Similar Posts

TheDailyWTF.com: Client-Side PHP

PHP Discovery Blog: Dangers of Remote Execution

Netbeans Blog: Code Completion for the Kohana & Code-igniter Frameworks

DevShed: PHP Programs to Prevent MySQL Injection or HTML Form Abuse

PHPMaster.com: Say Hello to Boris: A Better REPL for PHP


Community Events











Don't see your event here?
Let us know!


package composer security component framework opinion podcast release install introduction facebook language symfony2 unittest application overview code example hack hhvm

All content copyright, 2014 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework