1. One user per application
Each application gets its own database user with access only to its own database. Managing database users and privileges
2. Strong, unique passwords
Generate them. Never reuse a database password for anything else.
3. Prevent SQL injection
Never build SQL with user input:
// Unsafe
$db->query("SELECT * FROM users WHERE email = '$_POST[email]'");
// Safe
$stmt = $pdo->prepare('SELECT * FROM users WHERE email = ?');
$stmt->execute([$_POST['email']]);
Connecting a PHP application to your database
4. Keep credentials out of reach
- Store configuration outside
public_htmlwhere possible. Storing configuration and secrets outside public_html - Never commit credentials to a public Git repository.
- Remove backup copies like
wp-config.php.bakorconfig.oldfrompublic_html: the server may serve them as plain text.
5. Don’t leave SQL dumps in public_html
A backup.sql file in the web root can be downloaded by anyone who guesses the name. Store exports off the server.
6. Keep phpMyAdmin access to trusted devices
Log out when finished, especially on shared computers.
7. Back up
A secure database you can’t restore is still a single point of failure. A simple backup strategy for your website
Looking for somewhere to run PHP and MySQL? Traxio’s free PHP MySQL hosting includes phpMyAdmin and is free for your first 30 days.