Unless you've made the code, then it's quite hard. You're always at the mercy of the developer.
e.g. With Wordpress, you have to rely on the plugin developers being security conscious.
The best you can hope for is to secure your mysql install. (disable root, disable remote, etc)