Hey Scott, thanks for taking the time to post this, and on behalf of the PHP community, allow me to apologize. :) Your first bullet point there was at least partially if not completely my fault. What can I say? I was young and stupid. Anyway...
Well, informally, rules are sort of what we do here. You're coming to us with something very high-level which, in principle, everyone here probably agrees with. We're just not sure what to do with it. Generally speaking, the standards recommendations we publish are a formalization of what the community is already doing, and most of us tend to shy away from anything that could be perceived to be dictatorial.
If there was an opportunity to roll this up into a higher-level 'security guidelines' PSR, I think that might make sense. In the meantime, I would echo the previous suggestions of PHP the Right Way as a pretty good venue.