I read some hosting company stated that:
Apache's mod_php3: Everything which run as the web server's username, which is not secure. You should use the external shell instead, and run your php3 as CGI.
However, my hosting company is using apache's mod_php. Is that safe?