Everyone argues about eval() and security. What gets discussed less: a formula has to fail when you write it, not on the first number, and you need the dependency order before any value exists.
A tokenizer and a recursive-descent parser give you that. eval() gives you none of it. https://shipmindlabs.com/c/a8242fe4