Routes setup:di:compile to a trusted Rust binary for faster code generation, with a Composer installer, timeout/jobs controls, and a --standard fallback to the PHP compiler.
Details how APSB26-146 closes three issues—unsafe object instantiation reachable from CMS/email templates, untyped preview inputs, and writable error reports—and outlines patching steps plus checks to catch similar instantiate-then-check anti-patterns.
Patch enforcing CLI-only execution for DI scanners to mitigate StyleSmuggler, adding PHP_SAPI checks in ArrayScanner, ClassesScanner, and XmlInterceptorScanner.
Composer package running an MCP server with 80+ tools to inspect runtime DI resolution, plugin chains, events, EAV attributes, routes, GraphQL, and more. Includes error/performance diagnostics, a read‑only code runner, code generation, and container-aware setup with production-safe defaults.