There are a bunch of internal functions that the plugin doesn't know how to handle. A couple of good lists:
- https://www.php.net/manual/en/taint.detail.untaint.php
- https://www.php.net/manual/en/taint.detail.taint.php
This would be along the lines of https://gerrit.wikimedia.org/r/c/mediawiki/tools/phan/SecurityCheckPlugin/+/599301