http://www.cyberciti.biz/tips/php-security-best-practices-tutorial.html
PHP is an open-source server-side scripting language and it is a widely used. The Apache web server provides access to files and content via the HTTP OR HTTPS protocol. A misconfigured server-side scripting language can create all sorts of problems. So, PHP should be used with caution. Here are twenty-five
php security best practices for sysadmins for configuring PHP securely.