So what's the actual way of doing this in PHP?
There are pdo drivers for most popular databases
https://www.php.net/manual/en/book.pdo.php
Honestly it’s my favorite way of accessing databases (compared with Java Perl and python)
These eliminate SQL injection. But you have to use them and not just concatenate user input to SQL queries.
$stmt = $pdo->prepare('INSERT INTO user (email) VALUES(?)');
$stmt->execute([$email]);
For a full example you can look here, includes injection exampleIf it's raw PHP I wouldn't want to compete with a lot of great SO results out there, but you also have to take into account circumstantial matters, like whether the given approach is appropriate to the needed output or input you are dealing with.
For this reason I'd recommend arranging for some kind of code review even if you ask online strangers for input.