News

If PHP's MySQL library supports it, you should be using bound variables. Gets rid of the SQL-injection worries.