Here are a few links my host gave me when i ran into the same problem:
<a href="http://www.tech-faq.com/source-code-security-vulnerabilities.shtml" rel="nofollow">http://www.tech-faq.com/source-code-security-vulnerabilities...</a>
<a href="http://www.fortify.com/landing/extra/ppc_source_code.html?source=goog&kw=source_code_security&gclid=CP3piJXu-pUCFRg6awodsQaYFA" rel="nofollow">http://www.fortify.com/landing/extra/ppc_source_code.html?so...</a>
<a href="http://sectools.org/" rel="nofollow">http://sectools.org/</a>