LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "2.5.7"
}
]
}