Tag
prepared-statements
Safeguard articles tagged "prepared-statements" — guides, analysis, and best practices for software supply chain and application security.
3 articles
Best Practices
Parameterized queries across languages: the real defense against SQL injection
SQL injection (CWE-89) still ranks #3 on the OWASP Top 10, but every major language has shipped a native, built-in fix for over a decade — most breaches happen anyway.
Jul 8, 20267 min read
Open Source
Is the npm mysql Package Safe? A Security Review
A security-focused look at the npm mysql driver: SQL injection risks, prepared statements, connection handling, and why most teams should move to mysql2.
May 27, 20256 min read
AppSec
SQL Injection Demo: How the Attack Works and How to Stop It
A practical SQL injection demo that shows how unsanitized input reaches the database, why it works, and the one fix that reliably closes the hole.
Feb 11, 20256 min read
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.