PHP Medium technical 0 views 1 min read

How do you prevent SQL injection in PHP?

Peer-reviewed by HireXTech Technical Panel Updated for 2025/2026 hiring Editorial standards
Practise this track
Interviewer Expectations for this Question
01
Core Competency

Assesses fundamental understanding of PHP conventions, runtime behavior, and memory/performance considerations.

02
Evaluation Criteria

Hiring managers look for precision, avoidance of ambiguous jargon, and ability to explain trade-offs under real production conditions.

Comprehensive Model Answer Verified Solution

Never concatenate user input into SQL. Use prepared statements with bound parameters, which separate code from data.

$stmt = $pdo->prepare('SELECT * FROM users WHERE email = :email AND active = 1');
$stmt->execute([':email' => $email]);
$user = $stmt->fetch();

Also:

  • Use PDO or mysqli with emulation disabled (PDO::ATTR_EMULATE_PREPARES => false).
  • Validate and whitelist anything that cannot be bound, such as column names or ORDER BY direction.
  • Apply least privilege to the database user and escape output with htmlspecialchars for XSS.
  • Store passwords with password_hash and verify with password_verify.

Candidate Response Strategy & Interview Tips

  1. Start with a concise one-sentence summary: Deliver a direct, confident answer first before expanding into nuances.
  2. Demonstrate real-world trade-offs: Discuss where this approach excels and when you would avoid it in production systems.
  3. Discuss complexity & edge cases: Proactively explain time/space complexity or boundary conditions (null values, scale limits).
  4. Prepare for interviewer follow-ups: Technical hiring panels frequently probe deeper into concurrency, backward compatibility, or alternative libraries.
Spotted an error or have an alternative solution?