I think the project file ( name.settings ) should not be 
saved where the php files resides ( under the server's 
DOC_ROOT ) since that could expose details about the 
filesystem. The project files should be saved inside the 
PHPDE install folder ( a "Projects" subfodler maybe ) and 
only the project's files showuld be stores in the 
DOC_ROOT
Logged In: YES
user_id=1216235
Assigned to Gareth for study purposes.
File is project.settings, created when making a project or
importing an existing project.
Look at the XML file structure / content and determine any
possible security breeches / problems with its content.
Logged In: YES
user_id=1216235
...still assigned to Gareth...