Not an expert, but here's what I've gathered from teh Interwebs:
http://en.wikipedia.org/wiki/PHP#Security
http://en.wikipedia.org/wiki/Cross-site_scripting
Pay special attention to what the non-contributing code does or seems to be trying to do.
http://en.wikipedia.org/wiki/PHP#Security
http://en.wikipedia.org/wiki/Cross-site_scripting
Pay special attention to what the non-contributing code does or seems to be trying to do.