prevent SQL Injection in PHP?

Use Prepared Statements with PDO or mysqli.

$stmt = $conn->prepare("SELECT * FROM users WHERE email = ?");
$stmt->bind_param("s", $email);
$stmt->execute();

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *