{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T22:40:10Z","timestamp":1785537610249,"version":"3.56.0"},"publisher-location":"Cham","reference-count":25,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031687372","type":"print"},{"value":"9783031687389","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-68738-9_34","type":"book-chapter","created":{"date-parts":[[2024,9,8]],"date-time":"2024-09-08T23:02:40Z","timestamp":1725836560000},"page":"425-437","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":28,"title":["LLMs in\u00a0Web Development: Evaluating LLM-Generated PHP Code Unveiling Vulnerabilities and\u00a0Limitations"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-9574-1896","authenticated-orcid":false,"given":"Rebeka","family":"T\u00f3th","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2626-3434","authenticated-orcid":false,"given":"Tamas","family":"Bisztray","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4910-4228","authenticated-orcid":false,"given":"L\u00e1szl\u00f3","family":"Erd\u0151di","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,9,9]]},"reference":[{"key":"34_CR1","doi-asserted-by":"crossref","unstructured":"Fetzer, J.H.: Program verification: the very idea. Commun. ACM 31(9), 1048\u20131063 (1988). https:\/\/dl.acm.org\/doi\/10.1145\/48529.48530","DOI":"10.1145\/48529.48530"},{"key":"34_CR2","unstructured":"Hou, X., et al.: Large language models for software engineering: a systematic literature review. arXiv preprint arXiv:2308.10620 (2023)"},{"key":"34_CR3","doi-asserted-by":"crossref","unstructured":"Ross, S.I., Martinez, F., Houde, S., Muller, M., Weisz, J.D.: The programmers assistant: conversational interaction with a large language model for software development. In: Proceedings of the 28th International Conference on Intelligent User Interfaces, ser. IUI 2023, pp. 491-514. Association for Computing Machinery, New York (2023)","DOI":"10.1145\/3581641.3584037"},{"key":"34_CR4","doi-asserted-by":"publisher","unstructured":"Tihanyi, N., Bisztray, T., Jain, R., Ferrag, M.A., Cordeiro, L.C., Mavroeidis, V.: The formai dataset: Generative AI in software security through the lens of formal verification. In: Proceedings of the 19th International Conference on Predictive Models and Data Analytics in Software Engineering, ser. PROMISE 2023, p. 3343. Association for Computing Machinery, New York (2023). https:\/\/doi.org\/10.1145\/3617555.3617874","DOI":"10.1145\/3617555.3617874"},{"key":"34_CR5","unstructured":"Tihanyi, N., Bisztray, T., Ferrag, M.A., Jain, R., Cordeiro, L.C.: Do neutral prompts produce insecure code? formai-v2 dataset: labelling vulnerabilities in code generated by large language models. arXiv preprint arXiv:2404.18353 (2024)"},{"key":"34_CR6","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"332","DOI":"10.1007\/978-3-030-78120-0_22","volume-title":"ICT Systems Security and Privacy Protection","author":"A B\u00fcttner","year":"2021","unstructured":"B\u00fcttner, A., Nguyen, H.V., Gruschka, N., Lo Iacono, L.: Less is often more: header whitelisting as semantic gap mitigation in HTTP-based software systems. In: J\u00f8sang, A., Futcher, L., Hagen, J. (eds.) SEC 2021. IAICT, vol. 625, pp. 332\u2013347. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-78120-0_22"},{"key":"34_CR7","doi-asserted-by":"publisher","unstructured":"Kyriakakis, P., Chatzigeorgiou, A., Ampatzoglou, A., Xinogalos, S.: Evolution of method invocation and object instantiation patterns in a PHP ecosystem. In: Proceedings of the 20th Pan-Hellenic Conference on Informatics (2016). https:\/\/doi.org\/10.1145\/3003733.3003777","DOI":"10.1145\/3003733.3003777"},{"key":"34_CR8","unstructured":"Smart, D., Dillon: PHP Statistics in 2022 | PHP Marketshare | Laravel Statistics (2022). https:\/\/iknowthatnow.com\/2022\/04\/11\/2022-php-statistics\/"},{"key":"34_CR9","doi-asserted-by":"crossref","unstructured":"Van den Brink, W., Gerhold, M., Zaytsev, V.: Deriving modernity signatures for PHP systems with static analysis. In: Proceedings of the 2022 IEEE 22nd International Working Conference on Source Code Analysis and Manipulation (SCAM), Limassol, Cyprus, pp. 181\u2013185 (2022)","DOI":"10.1109\/SCAM55253.2022.00027"},{"key":"34_CR10","unstructured":"Nehorai, N.: Analyzing common vulnerabilities introduced by code-generative AI (2024). https:\/\/hackernoon.com\/analyzing-common-vulnerabilities-introduced-by-code-generative-ai"},{"key":"34_CR11","doi-asserted-by":"publisher","unstructured":"Perry, N., Srivastava, M., Kumar, D., Boneh, D.: Do users write more insecure code with AI assistants?\" (2022). https:\/\/doi.org\/10.1145\/3576915.3623157","DOI":"10.1145\/3576915.3623157"},{"key":"34_CR12","unstructured":"Charalambous, Y., Tihanyi, N., Jain, R., Sun, Y., Ferrag, M.A., Cordeiro, L.C.: A new era in software security: Towards self-healing software via large language models and formal verification. arXiv preprint arXiv:2305.14752 (2023)"},{"key":"34_CR13","unstructured":"OpenAI: GPT-4 Technical Report. arXiv preprint arXiv:2303.08774 (2024)"},{"key":"34_CR14","unstructured":"Fajkovic, E., Rundberg, E.: The impact of ai-generated code on web development: a comparative study of Chatgpt and Github copilot, Dissertation, Blekinge Institute of Technology, Faculty of Computing, Department of Software Engineering (2023)"},{"key":"34_CR15","doi-asserted-by":"crossref","unstructured":"Dong, Y., Jiang, X., Jin, Z., Li, G.: Selfcollaboration code generation via Chatgpt. arXiv preprint arXiv:2304.07590 (2023)","DOI":"10.1145\/3672459"},{"key":"34_CR16","doi-asserted-by":"publisher","unstructured":"Monteiro, M., Castelo Branco, B., Silvestre, S., Avelino, G., Valente, M.T.: End-to-end software construction using Chatgpt: an experience report. arXiv preprint arXiv:2310.14843 (2023). https:\/\/doi.org\/10.48550\/arXiv.2310.14843","DOI":"10.48550\/arXiv.2310.14843"},{"key":"34_CR17","doi-asserted-by":"crossref","unstructured":"Alrashedy, K., Hellendoorn, V.J., Orso, A.: Learning defect prediction from unrealistic data. In: Proceedings of the IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER 2024) (2024)","DOI":"10.1109\/SANER60148.2024.00063"},{"key":"34_CR18","doi-asserted-by":"publisher","unstructured":"Chen, Y., Ding, Z., Alowain, L., Chen, X., Wagner, D.: DiverseVul: a new vulnerable source code dataset for deep learning based vulnerability detection. In: Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses, pp. 654-668, ser. RAID 2023, Hong Kong, China (2023). https:\/\/doi.org\/10.1145\/3607199.3607242","DOI":"10.1145\/3607199.3607242"},{"key":"34_CR19","doi-asserted-by":"publisher","unstructured":"Tihanyi, N., Bisztray, T., Jain, R., Ferrag, M.A., Cordeiro, L.C., Mavroeidis, V.: FormAI dataset: a large collection of AI-generated C programs and their vulnerability classifications. IEEE Dataport (2023). https:\/\/doi.org\/10.21227\/vp9n-wv96","DOI":"10.21227\/vp9n-wv96"},{"key":"34_CR20","unstructured":"Gadde, N., Kumar, D., Nalapat, A., Rezunov, E., Cappellini, F.: All artificial, less intelligence: GenAI through the lens of formal verification. In: Proceedings of DVCon U.S. 2024. arXiv preprint arXiv:2403.16750 (2024)"},{"key":"34_CR21","unstructured":"Guo, D., et al.: DeepSeek-coder: when the large language model meets programming\u2013the rise of code intelligence. arXiv preprint arXiv:2401.14196 (2024). https:\/\/arxiv.org\/abs\/2402.03300v3"},{"key":"34_CR22","unstructured":"Open Web Application Security Project (OWASP): Owasp top 10 - 2021: The ten most critical web application security risks. https:\/\/owasp.org\/www-project-top-ten\/ (2021). Accessed 16 Mar 2024"},{"key":"34_CR23","unstructured":"MITRE: Common Weakness Enumeration (CWE) - A Community-Developed List of Common Software and Hardware Weakness Types. https:\/\/cwe.mitre.org\/ (2024). Accessed 27 Mar 2024"},{"key":"34_CR24","doi-asserted-by":"crossref","unstructured":"Wallace, D., Fujii, R.: Software verification and validation: an overview. IEEE Software, vol. 6, no. 3, pp. 10\u201317 (1989). http:\/\/ieeexplore.ieee.org\/document\/28119\/","DOI":"10.1109\/52.28119"},{"key":"34_CR25","unstructured":"PortSwigger Web Security: Burp suite documentation. https:\/\/portswigger.net\/burp\/documentation\/ (2024). Accessed 16 Mar 2024"}],"container-title":["Lecture Notes in Computer Science","Computer Safety, Reliability, and Security. SAFECOMP 2024 Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-68738-9_34","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,8]],"date-time":"2024-09-08T23:09:48Z","timestamp":1725836988000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-68738-9_34"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031687372","9783031687389"],"references-count":25,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-68738-9_34","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"9 September 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SAFECOMP","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Computer Safety, Reliability, and Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Florence","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 September 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"43","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"safecomp2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.safecomp2024.unifi.it\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}