Security is more reliable when it is built into shared helpers instead of copied into individual pages.
Use prepared statements everywhere
Do not concatenate user input into SQL. Prepared statements make the safe approach the normal approach.
Protect state-changing forms
Use CSRF tokens and server-side validation for create, update and delete actions.
Validate uploads on the server
- Inspect the MIME type.
- Generate your own filename.
- Limit file size.
- Block PHP execution in upload directories.