Hi @mecanik ! Thank you for taking the time to write a review.
Please note that this plugin is not meant to be run on production sites, and is only intended for plugin developers to test their code for certain issues, in a development environment. This means that the dangers of executing code via shell_exec() is not a big issue.
I do agree that this should be mentioned somewhere. Please use the Github issue form to submit an issue about this, so the developers can take a look.
Hi @mecanik,
We just released a version 0.2.2 that resolves that concern you present here.
Would love if you gave PCP another spin to see how it works for you.
Best regards,