Forms: GET and POST
| Read Array | |
| Read Array | |
| Validate input | |
| Escape output with htmlspecialchars |
Read $_GET
Data in the query string lands in the $_GET array. Use it for search,
filters, and pagination where the URL should stay shareable. See also
How to add variable to url in PHP.
Always assume the key may be missing and provide a default.
$q = $_GET["q"] ?? ""; $page = (int)($_GET["page"] ?? 1); echo $q; echo $page;
Read $_POST
Form submissions with method post fill the $_POST array.
Use it for logins, comments, and anything that changes data on the server.
Never place passwords or tokens into the query string when post is available.
$email = $_POST["email"] ?? ""; $message = $_POST["message"] ?? ""; echo $email; echo $message;
Validate input
Input from the browser is plain text and cannot be trusted. Check length, format,
and allowed values before using it in queries or business rules.
Reject bad data early with a clear message instead of trying to repair it silently.
$email = trim($_POST["email"] ?? ""); if ($email === "" || strlen($email) > 255) { echo "Email is required"; } elseif (filter_var($email, FILTER_VALIDATE_EMAIL) === false) { echo "Email looks wrong"; } else { echo "Email is ok"; }
Escape output with htmlspecialchars
When printing user data back into HTML, escape it with
htmlspecialchars. Without escaping, a value with angle brackets
can break markup or inject scripts.
Escape at output time, not at input time, so the stored value stays clean and reusable.
$name = $_GET["name"] ?? "guest"; echo htmlspecialchars($name, ENT_QUOTES, "UTF-8");
Next: HTTP: headers and status codes
Article author: Arthur Isaev