Send a small option identifier rather than trusting arbitrary option text from the browser. Validate the choice, verify the poll exists, and insert the vote with a prepared statement.
<?php
$qstId = filter_input(INPUT_POST, 'qst_id', FILTER_VALIDATE_INT);
$choice = filter_input(INPUT_POST, 'choice', FILTER_VALIDATE_INT);
if (!$qstId || !in_array($choice, [1, 2, 3, 4], true)) {
http_response_code(422);
exit('Invalid poll submission');
}
$stmt = $pdo->prepare(
'INSERT INTO plus_poll_ans (qst_id, opt) VALUES (:qst_id, :opt)'
);
$stmt->execute(['qst_id' => $qstId, 'opt' => $choice]);
?>
For a production poll, combine this with CSRF validation and your chosen duplicate-vote policy. When calculating results, prefer aggregate queries such as COUNT(*) ... GROUP BY instead of fetching rows only to count them in PHP.
session_start();
$s_id=session_id();
require "config.php";
$opt=$_POST['opt'];
$qst_id=$_POST['qst_id'];
if(!isset($opt)){echo "<font face='Verdana' size='2' color=red>Please select one option and then submit</font>";}
else{
$sql=$dbo->prepare("insert into plus_poll_ans(s_id,qst_id,opt) values(:s_id,:qst_id,:opt)");
$sql->bindParam(':s_id',$s_id,PDO::PARAM_STR, 100);
$sql->bindParam(':qst_id',$qst_id,PDO::PARAM_INT, 1);
$sql->bindParam(':opt',$opt,PDO::PARAM_STR,2);
if($sql->execute()){
//$mem_id=$dbo->lastInsertId();
echo "Thanks for your views, Please <a href=view_poll_result.php>click here to view the poll result</a> or click here to visit the <a href=poll_display.php>php poll script tutorial</a>";
}
else{
echo " Not able to add data please contact Admin ";
}
//$qt=mysql_query("insert into plus_poll_ans(s_id,qst_id,opt) values('$s_id',$qst_id,'$opt')");
//echo mysql_error();
}
We will move to display result page to show the result to the visitor. As we have inserted the selected data to another table, we will collect all the records for which the question id = the current question id. This will display in selecting the result of current poll only. To display past poll results we can change the ID to different values. Let us set the question id to 1 for the first poll result to display. To calculate the percentage of the options selected we will also find out the total number of answers submitted. We will use number format function of PHP to display two decimal places for the figures in percentage. Then we will find out the answers by using sql group by function.
require "config.php";
//////////////////////////////
echo "<font size='2' face='Verdana' color='#000000'> The Poll from plus2net.com ( Poll ID = 1)</font>";
$qst_id=1; // change this to change the poll
/* Find out the question first */
$count=$dbo->prepare("select qst from plus_poll where qst_id=:qst_id");
$count->bindParam(":qst_id",$qst_id,PDO::PARAM_INT,3);
if($count->execute()){
//echo " Success <br>";
$row = $count->fetch(PDO::FETCH_OBJ);
}else{
echo "Database Problem";
}
echo "<br><b><br>$row->qst</b><br>"; // display the question
/* for percentage calculation we will find out the total number
of answers ( options submitted ) given by the visitors */
$count=$dbo->prepare("select ans_id from plus_poll_ans where qst_id=:qst_id");
$count->bindParam(":qst_id",$qst_id,PDO::PARAM_INT,3);
$count->execute();
$rt=$count->rowCount();
echo " No of records = ".$rt;
/* Find out the answers and display the graph */
$sql="select count(*) as no,qst,plus_poll_ans.opt from plus_poll,plus_poll_ans where plus_poll.qst_id=plus_poll_ans.qst_id and plus_poll.qst_id='$qst_id' group by opt";
echo "<table cellpadding='0' cellspacing='0' border='0' >";
foreach ($dbo->query($sql) as $noticia) {
echo "<tr>
<td width='40%' bgcolor='#F1F1F1'> <font size='1' face='Verdana' color='#000000'>$noticia[opt]</font></td>";
$width2=$noticia['no'] *10 ; /// change here the multiplicaiton factor //////////
$ct=($noticia[no]/$rt)*100;
$ct=sprintf ("%01.2f", $ct); // number formating
echo " <td width='10%' bgcolor='#F1F1F1'> <font size='1' face='Verdana' color='#000000'>($ct %)</font></td><td width='50%' bgcolor='#F1F1F1'> <img src='graph.jpg' height=10 width=$width2></td>
</tr>";
echo "<tr>
<td bgcolor='#ffffff' colspan=2></td></tr>";
//echo $noticia['sel'],$noticia[no]."<br>";
}
echo "</table>";
echo "</font>";
Author & Instructor at plus2net
I write and maintain practical tutorials on Python, PHP, SQL, JavaScript, HTML, jQuery, and web development at plus2net. The tutorials focus on clear explanations, working examples, and code that readers can test and adapt while learning.