As for script security it really is near impossible to stop all attacks.
Current mod_sec rules we have created blocks known wordpress hacks, long sql queries in url (sql injection), abusive sql queries, cross site exploits, etc...
Its very hard to offer such a security since most people use known scripts which the source codes have been either leaked or decrypted or even open gpl (public script).