You can pass an array of bindings to most raw query methods to avoid SQL injection.
// This is vulnerable to SQL injection$fullname = request('full_name');User::whereRaw("CONCAT(first_name, last_name) = $fullName")->get(); // Use bindingsUser::whereRaw("CONCAT(first_name, last_name) = ?", [request('full_name')])->get();
Tip given by @cosmeescobedo
Enjoyed This Tip?
Get access to all premium tutorials, video and text courses, and exclusive Laravel resources. Join our community of 10,000+ developers.
Recent Courses
[NEW] Laravel AI SDK: 6 Practical Examples
9 lessons
1 h 02 min
Livewire v3 to v4: Changes You Need to Know
7 lessons
31 min
Laravel Coding with AI Agents: Cursor, Claude Code, Codex
5 lessons
1 h 01 min