php-taint is a PHP extension for detecting cross-site scripting (XSS) and SQL-injection vulnerabilities.

WWW: https://github.com/laruence/taint
