We give the first characterization of these types of vulnerabilities in PHP applications, develop novel inter-procedural
algorithms for discovering them in PHP source code, and
implement these algorithms as part of SAFERPHP, a framework for static security analysis of PHP applications. SAFERPHP uncovered multiple, previously unreported vulnerabilities in several popular Web applications