But the author kind of made it seem like a big deal, while realistically nobody would write code this way. Taking user input, running the domain with host flag through filter var and then system call it?
Most libraries tend to implement validation themselves and not rely on filter_var.
But even if this was fixed, most people should know taking user input and running it via system is a bad idea and needs more than a simple filter_var filter.