/* - Sanitize Input - Helps reduce security risks and minimalises the possibility of SQL injection. $string - The string you wish to sanitize before entering into the database. $level - The level of security: > 1 = adds slashes to prevent SQL injection > 2 = adds slashes + htmlspecialchars to turn HTML tags into HTML entities (eg. becomes <html>) > 3 = add slashes + strip_tags to remove all HTML tags. */ public function sanitizeInput($string, $level = 1) { switch ($level) { case 1: $string = addslashes($string); break; case 2: $string = htmlspecialchars(addslashes($string)); break; case 3: $string = strip_tags(addslashes($string)); break; } return $string; }