Pro PHP Security: From Application Security Principles to the Implementation of XSS Defenses (Expert's Voice in Open Source) by Chris Snyder (10-Dec-2010) Paperback
Definitely more thorough and up-to-date than most PHP security books. You should still visit StackOverflow just in case (and as time wears on, to stay up-to-date), but this book is surprisingly useful.