"Did they implement defenses against common web vulnerabilities like SQL injection?"
Prepared statements has been available with PDO since 2005. It might very well have had bugs, but that isn't uncommon.
Prepared statements has been available with PDO since 2005. It might very well have had bugs, but that isn't uncommon.