file_uploads
is an on-by-default PHP configuration that allows files to be uploaded to your site. Since accepting candy
files from strangers is inherently dangerous, this feature should be disabled unless it is absolutely necessary for your site.
This rule raises an issue when file_uploads
is not explicitly disabled.
Noncompliant code example
; php.ini
file_uploads=1 ; Noncompliant
Compliant solution
; php.ini
file_uploads=0