So apparently the streams API is deep magic that malware will never use? If you're going to pass around "cargo cult crap" (thanks McGlockenshire), at least make sure you're locking down _every_ equivalent of "dangerous function" that only malware and "badly written software" supposedly would use. To add a few to the holes others have listed, you should disable proc_open, popen, pcntl_exec. How about dl(), to close a (rare) vector for loading native code?
While we're doing drop-in magic stuff to mitigate problems, don't forget to put libxml_disable_entity_loader(true);
at the beginning of every script.[0]
Why not disable file_put_contents? I always thought that was kind of a shoddy practice, and likely to appear in malware, too!
Why not set allow_url_include = off ? Surely this is in "badly written software" territory that is exploited by malware?
Obviously this isn't exhaustive, either. My point is that you can't wave a few boilerplate configurations over any PHP application to make it secure. That may be a sizable flaw in the platform, but if so, say that rather than trying to give people copy-paste "protection."
[0] https://www.idontplaydarts.com/2011/02/scanning-the-internal...