Forms: GET and POST

Contents
Read Array
Read Array
Validate input
Escape output with htmlspecialchars

Read $_GET

Data in the query string lands in the $_GET array. Use it for search, filters, and pagination where the URL should stay shareable. See also How to add variable to url in PHP.

Always assume the key may be missing and provide a default.

$q = $_GET["q"] ?? ""; $page = (int)($_GET["page"] ?? 1); echo $q; echo $page;

Read $_POST

Form submissions with method post fill the $_POST array. Use it for logins, comments, and anything that changes data on the server.

Never place passwords or tokens into the query string when post is available.

$email = $_POST["email"] ?? ""; $message = $_POST["message"] ?? ""; echo $email; echo $message;

Validate input

Input from the browser is plain text and cannot be trusted. Check length, format, and allowed values before using it in queries or business rules.

Reject bad data early with a clear message instead of trying to repair it silently.

$email = trim($_POST["email"] ?? ""); if ($email === "" || strlen($email) > 255) { echo "Email is required"; } elseif (filter_var($email, FILTER_VALIDATE_EMAIL) === false) { echo "Email looks wrong"; } else { echo "Email is ok"; }

Escape output with htmlspecialchars

When printing user data back into HTML, escape it with htmlspecialchars. Without escaping, a value with angle brackets can break markup or inject scripts.

Escape at output time, not at input time, so the stored value stays clean and reusable.

$name = $_GET["name"] ?? "guest"; echo htmlspecialchars($name, ENT_QUOTES, "UTF-8");

Next: HTTP: headers and status codes

Article author: Arthur Isaev

Related articles
Development with PHP
PHP course: zero to hero in 50 lessons
What is PHP and where it runs
Install PHP 8.5 and run your first command
Your first PHP script
Comments in PHP
Variables and constants
Types in PHP
Strings in PHP
Numbers in PHP
Operators
if and else
switch and match
Ternary, null coalescing and nullsafe
Loops
Arrays
Associative arrays
Functions
Variable scope
include and require
Namespaces
Composer and autoloading
Everyday string functions
Dates and time
JSON in PHP
Reading and writing files
Errors: read, reproduce, fix
Classes and objects
Constructors and promotion
Inheritance
Interfaces and traits
Enums
Magic methods
Attributes
Exceptions
Strict types
Closures and arrow functions
Generators with yield
Forms: GET and POST
HTTP: headers and status codes
Cookies
Sessions
Login with sessions
JSON REST endpoint
Database with PDO
Uploads and .htaccess
Lint like a pro
Clean functions
Debugging
Modern PHP tour: 5 to 8.4
PHP 8.5 for busy developers
Hero roadmap: the whole course on one page
Install PHP 8.5 on Windows 11
Install PHP 8.5 on Ubuntu
Install PHP 8.5 on Rocky Linux
Install PHP 8.5 on macOS
Install PHP 8.5 on FreeBSD
PHP 8.5 in Docker

Search this site

Channel @aofeed Chat @aofeedchat

Contacts and cooperation:
I recommend our hosting beget.ru
Write to info@urn.su if you:
1. Want to write an article for our site or translate an article into your native language.
2. Want to place thematically relevant ads on the site.
3. Ads on my site pass maximum censorship. If you see an ad block unsuitable for school-age children, shocking or misleading - please contact us by e-mail
4. Found a mistake, inaccuracy, bug, etc. on the site. ... .......
5. Articles can be shared on social media by clicking a network icon: