Prepared statement with PDO Php Placeholders rather than interpolation. This is the whole of SQL injection defence in PHP. PHP php pdo security sql chris