What you should be using is quoting and escaping for the specific context.
Here in PHP and in the shell command argument position, you'd use `escapeshellarg()`. This will produce a correctly quoted and escaped string that can be safely used at argument position in a shell command.
It also doesn't rely on knowledge of the specific domain of the argument and it doesn't parse the argument at all. It's stateless and works everywhere.
Of course, if the input isn't a valid hostname, to come back to this article, `ping` will still fail, but there will be no possibility for arbitrary code execution (of course, neither their would be if `filter` worked right, but that's a) accidental (because ; and ' are not valid host name characters) and b) obviously not a given because filtering and sanitisation is much harder than dumb quoting.
Always quote. Only validate if you need to produce a readable error message. But never rely on validation or sanitisation.
That is if you actually use raw php. Very few (good) people do. (Kinda like ruby). And symfony / laravel have functions for both these use cases. Symfonys process takes care of this for example