Placeholders rather than interpolation. This is the whole of SQL injection defence in PHP.
Category
Snippets in PHP
htmlspecialchars with the flags spelled out, because the defaults have changed between versions.
password_hash picks the algorithm and the salt. Never store anything a hash function can reverse.