I'm using skipfish for the security scan. What are you guys using?
https://wiki.mozilla.org/WebAppSec/Secure_Coding_Guidelines