
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
@codemirror/lang-php
Advanced tools
[ WEBSITE | ISSUES | FORUM | CHANGELOG ]
This package implements PHP language support for the CodeMirror code editor.
The project page has more information, a number of examples and the documentation.
This code is released under an MIT license.
We aim to be an inclusive, welcoming community. To make that explicit, we have a code of conduct that applies to communication around the project.
import {EditorView, basicSetup} from "codemirror"
import {php} from "@codemirror/lang-php"
const view = new EditorView({
parent: document.body,
doc: `<? echo "Hello world" ?>`,
extensions: [basicSetup, php()]
})
php(config?: Object = {}) → LanguageSupport
PHP language support.
config
baseLanguage?: Language
By default, the parser will treat content outside of <?
and
?>
markers as HTML. You can pass a different language here to
change that. Explicitly passing disables parsing of such content.
plain?: boolean
By default, PHP parsing only starts at the first <?
marker.
When you set this to true, it starts immediately at the start of
the document.
phpLanguage: LRLanguage
A language provider based on the Lezer PHP parser, extended with highlighting and indentation information.
6.0.2 (2025-06-19)
Add a .d.cts file to make TypeScript happy.
FAQs
PHP language support for the CodeMirror code editor
We found that @codemirror/lang-php demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.