How can PHP developers prevent SQL injection vulnerabilities when using user input in database queries?

To prevent SQL injection vulnerabilities when using user input in database queries, PHP developers should use prepared statements with parameterized queries. This technique separates the SQL query from the user input, preventing malicious input from altering the query structure.

// Establish a database connection
$pdo = new PDO("mysql:host=localhost;dbname=mydatabase", "username", "password");

// Prepare a SQL statement with a parameterized query
$stmt = $pdo->prepare("SELECT * FROM users WHERE username = :username");

// Bind the user input to the parameter
$stmt->bindParam(':username', $_POST['username']);

// Execute the statement
$stmt->execute();

// Fetch the results
$results = $stmt->fetchAll();