$name = mysqli_real_escape_string($conn, $_POST['name']); $query = "SELECT * FROM users WHERE name='$name'";
$name = $_POST['name']; $stmt = $pdo->prepare("SELECT * FROM users WHERE name= ?"); $stmt->execute([$name]);In this example, PDO prepared statements are used to prepare the SQL query and escape the user input. Package library: PDO (PHP Data Objects) extension.