As I understand it, the CSPRNG check thing isn't a security feature, it's there in case the CSPRNG spits out an IV with the separator bytes in it. (That's also very silly, I'm just saying).
The strpos() check is what you're describing, but openssl_random_pseudo_bytes() accepts an optional second by-reference argument and sets it to true or false depending on the behavior of RAND_pseudo_bytes().
https://www.php.net/openssl_random_pseudo_bytes
This function also isn't fork-safe in PHP, and has caused RNG collisions before: https://github.com/ramsey/uuid/issues/80
Consequently, I advise against using this function entirely. random_bytes() is better in every way.
The strpos() check just prevents the IV from containing ::