The Plot to Kill PHP MySQL Extension
phpclasses.org
phpclasses.org
A better approach is to either (1) add a mysql_prepare() function to the PHP MySQL extension, or (2) deprecate the extension in favour of one which forces or at least encourages or at least supports the use of prepared statements.
Second of all, people should man up, step up from their lazy ass and move on. If the code is so really hard to refactor, maybe that code sucks really hard in the first place. I've seen incredible piles of garbage PHP code just to keep PHP 4 compatibility. It's 20-fu-11. 5 years since PHP 4 is officially dead. Maybe, just maybe, the internals team is not to blame for this stuff. I'm not even mentioning sentences containing the word "security" that seems to be some really scary stuff for some pumpkins still trying to figure out how SQLi works.