What is the recommended method for handling form submissions in PHP to avoid potential security risks?

To avoid potential security risks when handling form submissions in PHP, it is recommended to use prepared statements with parameterized queries to prevent SQL injection attacks. This method helps sanitize user input and ensures that data is properly escaped before being executed in a database query.

// Establish a database connection
$pdo = new PDO("mysql:host=localhost;dbname=mydatabase", "username", "password");

// Prepare a SQL statement with placeholders
$stmt = $pdo->prepare("INSERT INTO users (username, email) VALUES (:username, :email)");

// Bind parameters to the placeholders
$stmt->bindParam(':username', $_POST['username']);
$stmt->bindParam(':email', $_POST['email']);

// Execute the prepared statement
$stmt->execute();