If you do not plan to use it for security or authentication purposes, then $_SERVER['HTTP_HOST']
should be in order. You may have the wrong values ββfor your visitors to the kiddie script, but your regular users will use well-managed browsers.
You wonβt have security problems if you treat it like any other user. Sanitize it, do not create file names and do not execute commands on it, avoid it before displaying it, etc.
source share