Some quick research (with a grain of salt) indicates allow_url_fopen when used and coded correctly is fine (the risk is in the dodgy coding that might make it a vulnerability)...but allow_url_include is the one to avoid.
Statistics: Posted by AMurray — Sun Sep 15, 2024 4:52 am