Developer best practices at heart of application security

In a recent article at, Andy Gutmans, CEO of Zend—The company behind PHP—echoed one of the fundamental points I’ve been trying to make with this blog. That is that best practices, by the developer or development company, are at the heart of building a secure application:

“PHP, like all development languages, is only as secure as the code people write in it,” Gutmans said. “The important thing developers have to know is that when they deploy a Web application -- whether it’s written in PHP or in any other language -- they’re deploying into a hostile world.”

The article, discussing some non-critical security issues identified in PHP, states that "Among the reported issues are some that may be considered items that developer best practices can help to eliminate."

