What are some potential pitfalls to avoid when manipulating strings in PHP?

One potential pitfall to avoid when manipulating strings in PHP is not properly sanitizing user input, which can lead to security vulnerabilities such as SQL injection or cross-site scripting attacks. To prevent this, always use functions like `htmlspecialchars()` or `mysqli_real_escape_string()` when dealing with user input.

// Sanitize user input using htmlspecialchars
$user_input = "<script>alert('XSS attack');</script>";
$sanitized_input = htmlspecialchars($user_input);
echo $sanitized_input;