As seen on PHP-Magazine news, Angsuman Chakraborty has been doing a bit of security research of his own in hopes of determining whether PHP is inherently insecure as compared to Java and .NET based platforms.
A casual search at Secunia revealed 1599 Secunia Security Advisories. In contrast Java has 225 security vulnerabilities and much younger .NET platform has 827.
PHP based products has 5 Extremely Critical and 376 Highly Critical security vulnerabilities.
Interestingly I found 873 virus which can affects PHP files (based on search, didn't verify all of them individually).
Here however .NET is unbeatable with 8963 virus which affects its products. Java is a poor third with only 227 virus which can apparently affect it.




