esc_sql


esc_sql ( $data )

Parameters:
  • (string|array) $data Unescaped data
Returns:
  • (string|array) Escaped data
Defined at:

Description

Escapes data for use in a MySQL query.

Usually you should prepare queries using wpdb::prepare(). Sometimes, spot-escaping is required or useful. One example is preparing an array for use in an IN clause.

NOTE: Since 4.8.3, '%' characters will be replaced with a placeholder string, this prevents certain SQLi attacks from taking place. This change in behaviour may cause issues for code that expects the return value of esc_sql() to be useable for other purposes.

Related Functions

esc_js, esc_url, esc_html, is_ssl, esc_html__

Top Google Results

User discussions

wpseek mobile