I'd rather have ample documentation on how to harden my PHP application than no documentation on how to harden my Node application. Security through obscurity is no security at all. Plus, many of the mitigation strategies are simply rules like "don't use mysql_query" or "use htmlentities with ENT_QUOTES and UTF-8 to escape your output", both of which can be built into a framework. See: laravel.
[edit] downvoting is much easier than formulating a response, isn't it?
Why not Python, or Go, or even Haskell? There are many languages other than the three you mention which have much better reputations for secure web programming.
You likely got downvoted because you presented a false choice to back up your argument.
* The language itself has a pretty good security track record * The more popular application frameworks (Django, Flask, et al.) seem to be doing pretty well * Process isolation techniques are well-known