We're using smarty at work now, and while we probably won't drop it in this project (too much working code written in it), we might learn something for the future.
Otherwise PHP itself is a template language. That is why you start it with <? tag.
Just keep short tags on [it's off by default on new installations but ON by default on all hosting sites] and you got a better template engine than smarty.
You do not want to type <?php echo htmlspecialchars($var, ENT_QUOTES) ?> every time you want to output data. (Yes, I know it could probably be written shorter but my PHP is rusty. My point still remains though, you have to remember to type it every time.)
You can then run this entire array through htmlentities or htmlspecialchars before doing include().
My guess is that whoever wrote the framework just heard about Smarty while in university, long time ago.
Smarty's parser/lexer is horribly slow. The 3.1.x branch has caused problems for us, such as corrupted compiles and broken nested blocks [1]. As evidenced by the article, the developers don't seem to know what they're doing. You should see the workaround for people with custom error handlers -- registering another error handler on top that checks the source of the error against registered template and cache directory paths!
[1] The bug was introduced in this particular commit (lines 237-241 of r4505): https://code.google.com/p/smarty-php/source/diff?spec=svn450... and later "fixed" here: https://code.google.com/p/smarty-php/source/diff?spec=svn456...
I believe Twig is a fast and secure PHP template language.
I'm used to Jinja2 in Python which is almost identical to Twig.
Has anyone used Twig who would share their experience?
Really, PHP itself is a fine templating language if used properly. Get to know the short tags (including the short echo <?=$stuff?>) and the alternative syntax for conditional statements and you are good to go.