What are the best PHP input sanitizing functions?

后端 未结 13 1490
抹茶落季
抹茶落季 2020-11-21 23:31

I am trying to come up with a function that I can pass all my strings through to sanitize. So that the string that comes out of it will be safe for database insertion. But t

13条回答
  •  醉酒成梦
    2020-11-21 23:41

    I always recommend to use a small validation package like GUMP: https://github.com/Wixel/GUMP

    Build all you basic functions arround a library like this and is is nearly impossible to forget sanitation. "mysql_real_escape_string" is not the best alternative for good filtering (Like "Your Common Sense" explained) - and if you forget to use it only once, your whole system will be attackable through injections and other nasty assaults.

提交回复
热议问题