Disclaimer
This is not a question about whether we should be escaping for database input. This is strictly looking at the technical differences between the three functions in the title.
There is this question discussing the difference between htmlentities() and htmlspecialchars().  But, it doesn't really discuss filter_var() and the information I found on Google was more along the lines of "Make sure you escape user input before it is echo'd!"
My questions are:
- Why are htmlspecialchars()andhtmlentities()commonly used overfilter_var()?
- Is there some performance hit from using filter_var()?
- Is filter_var()not as secure as the other two options?
- Is there any other reason NOT to use the following to encode user input before being echod
filter_var($var, FILTER_SANITIZE_FULL_SPECIAL_CHARS);
 
     
    