For the longest time, I\'ve been using the following basic formatting for SQL queries within my PHP:
$sql = \"SELECT * FROM `user-data` WHERE `id` = \'\".$id.\"\
Try:
$stat2 = <<prepare($stat2); $status = $d_cur->execute(array($selected));