This paper presents a novel static analysis model called SCAT for identifying security vulnerabilities in PHP scripting languages. The model, which effectively detects issues such as cross-site scripting and SQL injection, achieved a 94% detection rate in benchmarks, demonstrating its practicality for enhancing web application security. The study evaluates SCAT against existing tools, highlighting its robustness and contribution to reducing vulnerability-related risks in web applications.