Short answer
SQL injection is when input from a visitor is passed into a database query without being handled safely, letting an attacker change what the query does. It is one of the oldest web vulnerabilities and still one of the most damaging.
This is a general web-hosting explanation, not specific to Traxio.
If you write your own PHP, prepared statements are the fix — they keep the query and the data separate so input can never be read as instructions. If you use WordPress, keeping plugins updated is the equivalent defence, because that is where these flaws get found and patched.
Learn more
- Keeping your databases secureProtect your website’s databases: separate users, strong passwords, prepared statements, safe credential storage and backups.
- Connecting a PHP application to your databaseThe connection details for Traxio databases and working examples with PDO and mysqli, including safe queries and keeping credentials private.
- Keeping website software updatedWhy updates are the most important security task, what needs updating beyond the CMS itself, and a routine that keeps a small site current.