What are the potential pitfalls of using mysql_escape_string() in PHP for data sanitization?

Using `mysql_escape_string()` for data sanitization in PHP is not recommended as it is deprecated and has been removed in newer versions of PHP. It is better to use `mysqli_real_escape_string()` or prepared statements to prevent SQL injection attacks.

// Using mysqli_real_escape_string() for data sanitization
$unsafe_data = "Unsafe data";
$safe_data = mysqli_real_escape_string($connection, $unsafe_data);