What are the best practices for constructing SQL queries in PHP when dealing with dynamic URL parameters?

When constructing SQL queries in PHP with dynamic URL parameters, it is important to use parameterized queries to prevent SQL injection attacks. This involves binding the parameters to placeholders in the query rather than directly interpolating them into the query string. By doing so, you ensure that the input values are properly sanitized and escaped, reducing the risk of malicious attacks.

// Example of constructing a SQL query with dynamic URL parameters using parameterized queries
$pdo = new PDO("mysql:host=localhost;dbname=mydatabase", "username", "password");

// Assume $param is a dynamic URL parameter
$param = $_GET['param'];

$stmt = $pdo->prepare("SELECT * FROM mytable WHERE column = :param");
$stmt->bindParam(':param', $param);
$stmt->execute();

// Fetch results
$results = $stmt->fetchAll(PDO::FETCH_ASSOC);

// Process results
foreach ($results as $row) {
    // Process each row
}