- Joined
- Apr 12, 2009
- Messages
- 104
- Reaction score
- 10
It is not secure. It can be escaped with the ` which is a valid character in strings. You should use some regular expressions and checks on things like hex ("0x") to be more secure. Also I suggest using mysql_real over the base one.

