I mean, in this case the developer really went out of their way to write bad code. TBH it kind of looks like they wanted to introduce an RCE vulnerability, since variable variable assignment is well-known even to novice PHP developers (who would also be the only ones using that feature), and "eval is bad" is just as well known.
A developer who has the aptitude to write a whois client, but knows neither of those things? It just seems very unlikely.
A developer who has the aptitude to write a whois client, but knows neither of those things? It just seems very unlikely.