How do i protect against SQL Injection if i wrote the site in PHP procedural? Can i use prepared statements? Or exists other ways?
example:
 $query ="INSERT INTO users (name,username,password,email,gender) VALUES ('$name','$username','$password','$email','$gender')";
 $result = mysqli_query($connect,$query) or die ( "Error : ". mysqli_error($connect) );
 
    