Your project uses dangerous command injection functions

More information: https://insight.symfony.com/what-we-analyse/php.use_command_injection_function

in scripts/init.php, line 156
  1. if ($overrides !== null) {
  2. $environment = \array_merge((array) \getenv(), $overrides);
  3. }
  4. $process = \proc_open(
    proc_open() is vulnerable to command injection attacks. Use the Symfony Process component instead.
    Time to fix: about 4 hours
    Read doc Open Issue Permalink Copy Prompt
    Last edited by Fery Wardiyanto
  5. $command,
  6. [
  7. 0 => ['pipe', 'r'],
  8. 1 => ['pipe', 'w'],
  9. 2 => ['pipe', 'w'],
  • feryardiant

    Ignored on Tue, 06 Oct 2026 20:33:42 GMT

Your project uses discouraged functions to kill scripts

More information: https://insight.symfony.com/what-we-analyse/php.use_exit_function

in scripts/init.php, line 718
  1. return true;
  2. }
  3. if (\realpath($_SERVER['SCRIPT_FILENAME'] ?? '') === __FILE__) {
  4. exit(main());
    This line stops the execution flow, without explanation. If this is for debug, you should remove it. If this is to deal with an error, use exceptions instead.
    Time to fix: about 4 hours
    Read doc Open Issue Permalink Copy Prompt
    Last edited by Fery Wardiyanto
  5. }
  • feryardiant

    Ignored on Tue, 06 Oct 2026 20:33:47 GMT