Man, I so wish I had published or even just posted it on a newsgroup (usenet). I discovered/thought of SQL injection in 1996 (with ColdFusion code), but my boss refused to let me disclose it to anyone (I was young then and actually listened to him).
He was going to do some big conference or something on the subject and drum up new business, but nothing ever came of it.
That's what I am trying to say.
Common security practices will put you out of danger. I'm confused why we should have recipes to 'secure PHP'. Why don't the regular security measures simply apply?
My guess is that many don't know what they are so they apply follow 'secure PHP' guides and feel safe, though they are not.
Here is an ancient example: NT Web Technology Vulnerabilities, written by rain.forest.puppy, Phrack Magazine Volume 8, Issue 54 Dec 25th, 1998.
http://www.phrack.org/issues.html?issue=54&id=8#article
This is one of the oldest articles on SQL injection I know of.