The unregister globals part is insecure. If I call the code with, say, index.php?modx=0 and register globals was on. Then the code just deleted our $modx variable.
Ow, and the cleanup function is still prone to XSS. If, for example, a GPC value would contain <a onmouseover="doEvilDeeds()"> the script would fail, and I’d still be able to inject your site. (At least, as far as I can tell by looking at the code).
Seems like a valid point you’ve got there
It’s absolutely okay to unset $myvariable, $modx, or whatever since the code occurs in the very first lines of index.php
.