im no server expert and the text was TLDR;
http://www.pcworld.com/businesscenter/article/246948/hackers_abuse_php_setting_to_inject_malicious_code_into_websites.html
"Always code as if the guy who ends up maintaining your code will be a violent psychopath who knows where you live."