What are the best practices for handling SQL queries in PHP to prevent SQL injection vulnerabilities?

To prevent SQL injection vulnerabilities in PHP, it is essential to use prepared statements with parameterized queries. This approach separates the SQL query logic from the user input, making it impossible for malicious input to alter the SQL query structure. By using prepared statements, you can ensure that user input is treated as data rather than executable code, effectively protecting your database from SQL injection attacks.

// Establish a database connection
$pdo = new PDO('mysql:host=localhost;dbname=mydatabase', 'username', 'password');

// Prepare a SQL statement with a parameterized query
$stmt = $pdo->prepare('SELECT * FROM users WHERE username = :username');

// Bind the user input to the parameter
$stmt->bindParam(':username', $_POST['username']);

// Execute the prepared statement
$stmt->execute();

// Fetch the results
$results = $stmt->fetchAll();