all code
1. never use registered globals.
2. do not use magic quotes. they are worthless and often get in the way. use mysql_real_escape_string() or similar functions as necessary.
3. in php-only files, omit the closing php tag. this ensures that the file will not print a new line at the end of the file. this is important to ensure that you can print headers, set cookies, and print doctypes properly.
distrubuted code (including all open-source projects)
1. never use short-open tags.
2. undo magic quotes at the beginning of every script (see example two,
disabling magic quotes at runtime ).
php environments
1. disable register_globals.
2. disable magic_quotes_gpc.
3. don't display php errors in production environments.
bsdlite
thinks darkness is his ally
nny
M̮͈̣̙̰̝̃̿̎̍ͬa͉̭̥͓ț̘ͯ̈́t̬̻͖̰̞͎ͤ̇ ̈̚J̹͎̿̾ȏ̞̫͈y̭̺ͭc̦̹̟̦̭̫͊̿ͩeͥ̌̾̓ͨ
nny
M̮͈̣̙̰̝̃̿̎̍ͬa͉̭̥͓ț̘ͯ̈́t̬̻͖̰̞͎ͤ̇ ̈̚J̹͎̿̾ȏ̞̫͈y̭̺ͭc̦̹̟̦̭̫͊̿ͩeͥ̌̾̓ͨ
Can you please explain that tip to my boss by the way? He insists on PHP :-(