I\'m trying to harden some of my PHP code and use mysqli prepared statements to better validate user input and prevent injection attacks.
I switched away from mysql
These are the characters not escaping by prepared statements % _ \