News Feed
Jobs Feed
Sections




News Archive
Looking for more information on how to do PHP the right way? Check out PHP: The Right Way

Sara Golemon's Blog:
create_function() is not your friend
May 21, 2007 @ 09:31:00

In response to this previous post from Felix Geisendorfer, Sara Golemon shares a few thoughts on why she thinks it's just the other way around - create_function is not your friend.

In the short post she lists just a few of the issues surrounding the use of the function including that it:

  • is prone to critical abuse by user-supplied code
  • skips opcode cache optimizations
  • encourages not using comments (evil)
  • 100% blind to reflection or PHPDoc style documentation generation

0 comments voice your opinion now!
createfunction eval abuse opcodecache reflection phpdoc createfunction eval abuse opcodecache reflection phpdoc


blog comments powered by Disqus

Similar Posts

Zend Developer Zone: Security Tips #10, #11, and #12

PHPEverywhere: Is PHP4 the new perl?

Vance Lucas' Blog: Get Only Public Class Properties for the Current Class in PHP

Chris Tankersley's Blog: Getting Started with Reflection

Netbeans Blog: Code Completion for the Kohana & Code-igniter Frameworks


Community Events











Don't see your event here?
Let us know!


introduction unittest performance composer support symfony2 framework hack application install language security component facebook hhvm package database podcast release opinion

All content copyright, 2014 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework