final class ExternalInput
Restricted visibility: declared "@visibility root". Code outside that scope must not name this declaration.

The places a value can enter the program from outside it.

A gap the analyzer can trace back to one of these is the difference between a query that is merely dynamic and one an attacker can steer.

Methods§

public function isVariable(string $name): bool
public function isFunction(string $name): bool

Whether calling that function reads something from outside the program.

Parameters

$namestring

Returns

bool
Test cases 1
Called from 1
Calls 3
public function isStream(string $target): bool

Whether reading that file reads the request body.

Parameters

$targetstring

Returns

bool
Test cases 1
Calls 1
  • function-call str_starts_with line 62

Private surface 2§

Implementation details, listed for orientation only.

private const VARIABLES = ['_GET' => true, '_POST' => true, '_REQUEST' => true, '_COOKIE' => true, '_SERV…
private const FUNCTIONS = ['getenv' => true, 'filter_input' => true, 'filter_input_array' => true, 'readl…

Test cases 87§

Test cases that cover or call this symbol, from the coverage report and from the analyzed test sources.

Dedicated tests 3
Other tests reaching this symbol 84

Relations§

Instantiated in 2
Method calls 3
Type declarations 6