Ed Filnker has posted a note about the slides that he presented as a part of the 8th Annual CERIAS Information Security Symposium.
The presentation [pdf] looks at the state of PHP development, the parties involved (including the "deployer") and the use of the PHPSecInfo application to help said "deployer" find issues they might miss otherwise. Of course, there's also a section on getting PHPSecInfo up and working on your system (you can unzip, right?) and other add-ons you can use to help avoid questions down the line (like the use of the Zend_Environment security module in the Zend Framework to test security).
Check out the PDF here and keep an eye on his blog for an upcoming video of the presentation.
UPDATE: he's also posted the audio for the presentation as well - grab the mp3.






 @phpdeveloper.org
 @phpdeveloper.org