addslashes function

addslashes — Quote string with slashes


string addslashes ( string $str )

Returns a string with backslashes added before characters that need to be escaped. These characters are:

  • single quote (')
  • double quote (")
  • backslash (\)
  • NUL (the NUL byte)

A use case of addslashes() is escaping the aforementioned characters in a string that is to be evaluated by PHP:

					$str = "O'Reilly?";
					eval("echo '" . addslashes($str) . "';");



the PHP directive magic_quotes_gpc was on by default and it essentially ran addslashes() on all GET, POST and COOKIE data. addslashes() must not be used on strings that have already been escaped with magic_quotes_gpc, as the strings will be double escaped. get_magic_quotes_gpc() can be used to check if magic_quotes_gpc is on.

The addslashes() is sometimes incorrectly used to try to prevent SQL Injection. Instead, database-specific escaping functions and/or prepared statements should be used.

Example 1

					$str = "Is your name O'Reilly?";

					// Outputs: Is your name O\'Reilly?
					echo addslashes($str);


	      		Is your name O\'Reilly?	      

Example 2

					$str = 'What does "WHO" mean?';  
					echo "Your string is :".$str;  
					echo "<br>"."By using addslashes() function the result  is".addslashes($str);   


	      		Your string is :What does "WHO" mean?
By using addslashes() function the result isWhat does \"WHO\" mean?

Example 3

					$str = "Who's the father of PHP?";  
					echo $str . " This is not safe in a database query.<br>";  
					echo addslashes($str) . " This is safe in a database query.";   


	      		Who's the father of PHP? This is not safe in a database query.
Who\'s the father of PHP? This is safe in a database query.

Example 4

					$str =  "Wow' PHP?";  
					eval("echo '" . addslashes($str) . "';");   


	      		Wow' PHP?	      

Example 5

					$str = "Is The Father of PHP'Rasmus?";  
					//Is The Father of PHP\'Rasmus?  
					echo addslashes($str);    


	      		Is The Father of PHP\'Rasmus?	      

