Learn PHP from Scratch

PHP and MySQL with PDO: CRUD and Security

Lesson 7 of 7 2 min read Updated 28 September 2026

Why PDO?

PDO (PHP Data Objects) is a modern, safe way to talk to databases. It supports prepared statements, which protect you from SQL injection, one of the most common web attacks.

Create a table

CREATE TABLE students (
  id INT AUTO_INCREMENT PRIMARY KEY,
  name VARCHAR(100) NOT NULL,
  email VARCHAR(150) NOT NULL UNIQUE,
  marks INT NOT NULL
);

Connect

<?php
$pdo = new PDO(
    "mysql:host=localhost;dbname=school;charset=utf8mb4",
    "db_user",
    "db_password",
    [
        PDO::ATTR_ERRMODE => PDO::ERRMODE_EXCEPTION,
        PDO::ATTR_DEFAULT_FETCH_MODE => PDO::FETCH_ASSOC,
    ]
);

Keep credentials in a config file outside the public web folder.

Create

$stmt = $pdo->prepare("INSERT INTO students (name, email, marks) VALUES (:name, :email, :marks)");
$stmt->execute([":name" => "Asha", ":email" => "asha@example.com", ":marks" => 88]);
echo "New ID: " . $pdo->lastInsertId();

Read

$stmt = $pdo->prepare("SELECT * FROM students WHERE marks >= :min ORDER BY marks DESC");
$stmt->execute([":min" => 60]);
foreach ($stmt->fetchAll() as $row) {
    echo htmlspecialchars($row["name"]) . " - " . $row["marks"] . "<br>";
}

Update and Delete

$pdo->prepare("UPDATE students SET marks = :m WHERE id = :id")
    ->execute([":m" => 91, ":id" => 1]);

$pdo->prepare("DELETE FROM students WHERE id = :id")
    ->execute([":id" => 1]);

The rule that prevents SQL injection

Never put user input directly into a SQL string.

// DANGEROUS - never do this
$pdo->query("SELECT * FROM students WHERE id = " . $_GET["id"]);

// SAFE
$stmt = $pdo->prepare("SELECT * FROM students WHERE id = :id");
$stmt->execute([":id" => $_GET["id"]]);

Practice

Build a student management page with a form to add students, a table to list them with search, and edit and delete buttons. Use POST and CSRF tokens for changes.

Next steps

Learn the WordPress course to see how PHP powers the world's most popular CMS.