See http://www.phpclasses.org/blog/post/206-Using-Grep-to-Find-Security-Vulnerabilities-in-PHP-code.html This is similar to a scanning utility I have for Fireproof Socks. Useful not just for MODX, but for any web app.