Yeah; the common idea of dignity and self-respect is to replace the duct tape with proper engineering once you're successful though, instead of just taping ever more of it on top and pretending SQL injections aren't really a problem.
Yeah; the common idea of dignity and self-respect is to replace the duct tape with proper engineering once you're successful though, instead of just taping ever more of it on top and pretending SQL injections aren't really a problem.
...but do they truly pretend SQL injections aren't really a problem, or do they in fact promote practices and provide pathways to reduce that risk?
What they do is put lipstick on a pig! There is no need to "reduce" the risk of SQL injections when you can use a safe API that eliminates the entire error class. This is a solved problem for the rest of the world!
PHP offers that safe API, though, and always has (prepared statements). The same one as all other languages.
PHP might seem worse than other languages due to a combination of factors:
- It's the most used one by far, even though few of us like to admit it.
- Old tutorials still come up during web searches, so "SELECT * FROM `table` WHERE id = $id" will still be written today.