Six of one, half a dozen of the other.
The aforementioned post is Stefan's attempt to show why suhosin is needed.
(I disagree personally, and I think Stefan's attitude is less than productive to the entire discussion.)
I think any project that doesn't take "security" fixes into consideration, doesn't use code-review and lets developers that clearly have no business changing security sensitive code commit bad code could use a good safe-gaurd that fixes those issues.
Yes, the time could be spent working on the core itself, but clearly that won't stop people from committing stuff they shouldn't be committing without having a qualified security guy checking off on it, so that won't help me have a secure running PHP installation...