What are the potential pitfalls of using DELETE queries in PHP, particularly when dealing with variables from SQL queries?

When using DELETE queries in PHP, particularly when dealing with variables from SQL queries, there is a risk of SQL injection if the variables are not properly sanitized. To prevent this, it is important to use prepared statements with placeholders for variables in the DELETE query. This ensures that the variables are treated as data rather than executable SQL code.

// Assuming $conn is the database connection

// Sanitize the input variable
$id = mysqli_real_escape_string($conn, $_GET['id']);

// Prepare the DELETE statement with a placeholder
$stmt = $conn->prepare("DELETE FROM table_name WHERE id = ?");
$stmt->bind_param("i", $id);

// Execute the statement
$stmt->execute();

// Close the statement and connection
$stmt->close();
$conn->close();