Nice work! I'm liking it, just one thing I've noticed:
On the page addavatar.php (I'm suppose there you submit the register info), yea well in there you're entering the var username to the database, but it seems like it isn't filtered, correct if I'm wrong please. You should fix that asap.





