Discussion on: Prevent SQL Injections

Jan van Brügge

No! Never sanatize your input! You will forget edge cases. Use prepared statements and nothing else (ORMs like ActiveRecords use prepared statements under the hood)

crishanks Author

Thanks for the feedback! Could be a good note to add the pros and cons of sanitized strings.