Skip to content

BacktickOperatorUsage ​

warning on by default quick-fix

Group: Security · PhpStorm name: BacktickOperatorUsageInspection

The backtick operator runs a shell command just like shell_exec(), but it is easy to overlook when reading code and security scanners often miss it. Calling shell_exec() explicitly makes command execution visible.

Example ​

php
<?php
$load  = `cat /proc/loadavg`;
$found = `grep -c "ERROR" app.log`;
function stamp() {
    return `date +%s`;
}
$nothing = ``;
$text = 'uses `backticks` in a plain string';
php
<?php
$load  = shell_exec("cat /proc/loadavg");
$found = shell_exec("grep -c \"ERROR\" app.log");
function stamp() {
    return shell_exec("date +%s");
}
$nothing = ``;
$text = 'uses `backticks` in a plain string';

Reported:

  • line 2: Run the command through shell_exec() instead of backticks.
  • line 3: Run the command through shell_exec() instead of backticks.
  • line 5: Run the command through shell_exec() instead of backticks.

Configure ​

In custos.json:

json
{
  "rules": {
    "BacktickOperatorUsage": {
      "enabled": false
    }
  }
}

Suppress ​

Before the statement or declaration (or the first statement of the file), either of:

php
// @custos-ignore BacktickOperatorUsage

/**
 * @noinspection BacktickOperatorUsageInspection
 */

Released under the MIT License. Rule catalogue modelled on Php Inspections (EA Extended); independent clean-room implementation.