PHP code is still audited manually. This is boring! Let's have PHP itself check its own dog food, and audit statically applications for security, code quality. It'll be faster, and more exhaustive than human, as long as we provide him with directions: here comes the cornac!