This is a proposal for PHP extension to disable running unapproved PHP code, uploaded using security holes or by any other means.
- Master key is saved in php.ini (hidden in phpinfo)
- Signatures are saved in a file that lives in web or app root folder, 1 line per file/signature