← Back to context

Comment by timbits98

1 day ago

...but do they truly pretend SQL injections aren't really a problem, or do they in fact promote practices and provide pathways to reduce that risk?

What they do is put lipstick on a pig! There is no need to "reduce" the risk of SQL injections when you can use a safe API that eliminates the entire error class. This is a solved problem for the rest of the world!

  • PHP offers that safe API, though, and always has (prepared statements). The same one as all other languages.

    PHP might seem worse than other languages due to a combination of factors:

    - It's the most used one by far, even though few of us like to admit it.

    - Old tutorials still come up during web searches, so "SELECT * FROM `table` WHERE id = $id" will still be written today.