Step 1. Get a good PHP coder to look at the script.
Step 2. Get an actual expert to do a security audit.
If you have no money to spend, there are some tips here:
appsec - How to perform a security audit for a PHP application? - Information Security Stack Exchange