BacktickOperatorUsage
warning on by default quick-fixGroup: Security · PhpStorm name: BacktickOperatorUsageInspection
The backtick operator runs a shell command just like shell_exec(), but it is easy to overlook when reading code and security scanners often miss it. Calling shell_exec() explicitly makes command execution visible.
Example
php
<?php
$load = `cat /proc/loadavg`;
$found = `grep -c "ERROR" app.log`;
function stamp() {
return `date +%s`;
}
$nothing = ``;
$text = 'uses `backticks` in a plain string';php
<?php
$load = shell_exec("cat /proc/loadavg");
$found = shell_exec("grep -c \"ERROR\" app.log");
function stamp() {
return shell_exec("date +%s");
}
$nothing = ``;
$text = 'uses `backticks` in a plain string';Reported:
- line 2: Run the command through shell_exec() instead of backticks.
- line 3: Run the command through shell_exec() instead of backticks.
- line 5: Run the command through shell_exec() instead of backticks.
Configure
In custos.json:
json
{
"rules": {
"BacktickOperatorUsage": {
"enabled": false
}
}
}Suppress
Before the statement or declaration (or the first statement of the file), either of:
php
// @custos-ignore BacktickOperatorUsage
/**
* @noinspection BacktickOperatorUsageInspection
*/