What actually goes wrong.
OUTDATED PHP OR DEPENDENCIES
Known vulnerabilities, publicly documented and scanned for.
QUERIES BUILT BY STRING JOINING
Injection.
OUTPUT NOT ESCAPED
Content executed in visitors' browsers.
PROTECTION DISABLED FOR CONVENIENCE
Cross-site request forgery.
ERRORS DISPLAYED IN PRODUCTION
Paths, versions and credentials revealed.
DEBUG MODE LEFT ENABLED
The same, with more detail.
UPLOADS IN AN EXECUTABLE DIRECTORY
Remote code execution.
CONFIGURATION FILES REACHABLE
Credentials disclosed.
IDENTIFIERS TRUSTED FROM INPUT
Access to other people's records.
PASSWORDS HASHED WITH GENERAL-PURPOSE FUNCTIONS
Recoverable in bulk after any breach.
NO RATE LIMITING
Credential guessing at scale.
BACKUPS LEFT IN THE PUBLIC DIRECTORY
Whole applications and databases downloaded.
WHAT PREVENTS MOST OF THESE
Updates, parameterised queries, escaping, and configuration outside the web root.