-
Notifications
You must be signed in to change notification settings - Fork 0
sqlEscape
Corey Avis edited this page Sep 23, 2026
·
2 revisions
Sanitizes a string for safe use in a MySQL query by escaping special characters. Depending on the parameters, it automatically wraps the value in single quotes for standard assignments or applies SQL wildcard characters (%) for LIKE clauses, ensuring both security and proper syntax formatting in one step.
sqlEscape(mixed $esc = null, bool $search = false): string
esc (mixed) : The value to escape.
search (bool)
: If set to true, then the value is wrapped in wildcards (%). ^(optional)^
(string) : Returns the escaped value.
$db->sqlEscape('value') = 'value'
$db->sqlEscape('term', true) = '%term%'
- No debug errors.