What potential pitfalls should be avoided when designing a PHP login system?

One potential pitfall to avoid when designing a PHP login system is storing passwords in plain text. Instead, passwords should be securely hashed using a strong hashing algorithm like bcrypt to protect user data in case of a data breach.

// Hashing the password before storing it in the database
$password = password_hash($_POST['password'], PASSWORD_BCRYPT);
```

Another pitfall to avoid is not properly sanitizing user input to prevent SQL injection attacks. Using prepared statements with parameterized queries can help protect against this vulnerability.

```php
// Using prepared statements to prevent SQL injection
$stmt = $pdo->prepare('SELECT * FROM users WHERE username = :username');
$stmt->bindParam(':username', $_POST['username']);
$stmt->execute();
```

Lastly, failing to implement proper session management can lead to security risks. Make sure to regenerate session IDs after a successful login to prevent session fixation attacks.

```php
// Regenerating session ID after successful login
session_regenerate_id(true);