Check out this link "Seven habits for writing secure PHP applications":
http://www.ibm.com/developerworks/opensource/library/os-php-secure-apps/index.html
The IBM articles are always very useful, thanks.
PS: also this "Recommended PHP reading list"
http://www.ibm.com/developerworks/opensource/library/os-php-read/#security