How do you prevent SQL injection in PHP?
Interviewer Expectations for this Question
01
Core Competency
Assesses fundamental understanding of PHP conventions, runtime behavior, and memory/performance considerations.
02
Evaluation Criteria
Hiring managers look for precision, avoidance of ambiguous jargon, and ability to explain trade-offs under real production conditions.
Comprehensive Model Answer
Verified Solution
Never concatenate user input into SQL. Use prepared statements with bound parameters, which separate code from data.
$stmt = $pdo->prepare('SELECT * FROM users WHERE email = :email AND active = 1');
$stmt->execute([':email' => $email]);
$user = $stmt->fetch();
Also:
- Use PDO or mysqli with emulation disabled (PDO::ATTR_EMULATE_PREPARES => false).
- Validate and whitelist anything that cannot be bound, such as column names or ORDER BY direction.
- Apply least privilege to the database user and escape output with htmlspecialchars for XSS.
- Store passwords with password_hash and verify with password_verify.
Candidate Response Strategy & Interview Tips
- Start with a concise one-sentence summary: Deliver a direct, confident answer first before expanding into nuances.
- Demonstrate real-world trade-offs: Discuss where this approach excels and when you would avoid it in production systems.
- Discuss complexity & edge cases: Proactively explain time/space complexity or boundary conditions (null values, scale limits).
- Prepare for interviewer follow-ups: Technical hiring panels frequently probe deeper into concurrency, backward compatibility, or alternative libraries.