What are some common pitfalls in PHP usage when creating a login screen?

One common pitfall in PHP usage when creating a login screen is not properly sanitizing user input, which can lead to SQL injection attacks. To prevent this, use prepared statements or parameterized queries to securely interact with your database.

// Using prepared statements to prevent SQL injection
$stmt = $pdo->prepare('SELECT * FROM users WHERE username = :username AND password = :password');
$stmt->execute(['username' => $username, 'password' => $password]);
$user = $stmt->fetch();
if ($user) {
    // User authenticated successfully
} else {
    // Invalid credentials
}