php8.5
Home/ Manual/ mysql / functions/ mysql_escape_string

mysql_escape_string

PHP function Edit on GitHub ✎

(PHP 4 >= 4.0.3, PHP 5)

Escapes a string for use in a mysql_query

4-3-0 mysqli_escape_stringPDO::quote

Description

mysql_escape_string(string $unescaped_string): string

This function will escape the unescaped_string, so that it is safe to place it in a mysql_query(). This function is deprecated.

This function is identical to mysql_real_escape_string() except that mysql_real_escape_string() takes a connection handler and escapes the string according to the current character set. mysql_escape_string() does not take a connection argument and does not respect the current charset setting.

Parameters

unescaped_string

The string that is to be escaped.

Return Values

Returns the escaped string.

Examples

mysql_escape_string() example

php
<?php
$item = "Zak's Laptop";
$escaped_item = mysql_escape_string($item);
printf("Escaped string: %s\n", $escaped_item);
?>

The above example will output:

output
Escaped string: Zak\'s Laptop

Notes

Note

mysql_escape_string() does not escape % and _.

See Also

Source: reference/mysql/functions/mysql-escape-string.xml · from the official PHP manual (php/doc-en)