allow_url_fopen is not a security issue - it only returns the code,
    it does not execute it.

    But yes you can use curl instead of relying on allow_url_fopen.

Well, allow_url_fopen is really a security issue. A renowned programmer ( said it could even cause DoS(Denial of Service) for the running server.

So can curl.

