addslashes() : Escape Special Characters

Add backslashes when that representation is specifically required

addslashes() escapes quotes, backslashes and NUL with backslashes. Do not use it as SQL-injection protection; use prepared statements for database queries.

$text = "O'Reilly";
echo addslashes($text); // O\'Reilly
The PHP addslashes() function is used to add backslashes before certain characters in a string. This is useful only when a receiving format specifically expects slash-escaped characters. It is not suitable for SQL escaping; database parameters must be bound separately.

Syntax

string addslashes ( string $string )
$string: The input string where special characters will be escaped by backslashes.
Return Value: A string with backslashes added before the following characters: single quote ('), double quote ("), backslash (\), and NULL.

Basic Example of addslashes()

In the following example, we apply the addslashes() function to escape quotes in a string.
$str = "John's book";
echo addslashes($str); // Output will add backslashes before the single quote
Output:
John\'s book

Example with Multiple Special Characters

This example demonstrates how addslashes() adds backslashes before multiple special characters in a string.
$str = 'He said, "It\'s a test!"';
echo addslashes($str); // Backslashes added before single and double quotes
Output:
He said, \"It\'s a test!\"

Example with Backslashes

The addslashes() function doesn't escape backslashes that are already part of the string
$str = "C:\\Program Files\\";
echo addslashes($str); // Backslashes are escaped too 
Output:
C:\\Program Files\\

Escaping NULL Characters with addslashes()

When using the addslashes() function, the NULL character (`\0`) is also escaped by adding a backslash. However, because NULL represents the end of a string in many contexts, it may not appear in regular output. To demonstrate this, we can use var_dump() to visualize the escaped NULL character.
$str = "A NULL character \0 is here.";
echo "Output with echo: " . $str . "<BR>"; // NUL may not display visibly in ordinary output

// To display the full string, including the escaped NULL, we use var_dump
var_dump(addslashes($str));
Output:
Output with echo: A NULL character
string(28) "A NULL character \0 is here."
As you can see, the addslashes() function adds a backslash before the NULL character, but the regular `echo` only prints up to the NULL character. Using var_dump(), we can see the full string including the escaped NULL.

Using addslashes() in SQL Queries

The addslashes() function is commonly used to escape special characters in SQL queries to prevent SQL injection.
$name = "O'Reilly";
$stmt = $mysqli->prepare('SELECT * FROM users WHERE name = ?');
$stmt->bind_param('s', $name);
$stmt->execute();
$result = $stmt->get_result();

The SQL value is bound separately instead of being inserted into the query string. Check errors and handle the result using your application's usual database flow.

Conclusion

Use addslashes() only for formats that explicitly require its escaping rules. Use prepared statements when querying a database, and htmlspecialchars() when safely displaying untrusted text in HTML.

String Functions Remove HTML tags


Subscribe to our YouTube Channel here



plus2net.com











PHP video Tutorials
✖
We use cookies to improve your browsing experience. . Learn more
HTML MySQL PHP JavaScript ASP Photoshop Articles Contact us
© 2000-2026 plus2net.com All rights reserved worldwide Privacy Policy Disclaimer