Advantages of using prepared statements over normal mysqli statements?

前端 未结 4 1857
花落未央
花落未央 2020-12-10 00:02

I have done my research and have decided to use prepared statements in my queries, all I ask if there is anything I should know, good or bad about switching to normal mysqli

4条回答
  •  心在旅途
    2020-12-10 00:45

    There are at least two advantages :

    • You don't have to deal with escaping values : it's done automatically (when using bound parameters, of course)
    • The statement is sent to the SQL server, prepared only once ; and, then, can be executed several times -- which is great for performances (the statement is parsed only once, even if executed lots of times)

提交回复
热议问题