在使用WordPress注释函数插入数据库时,是否需要针对MySQL注入准备字符串,例如:
$data = array(
\'comment_post_ID\' => $post_id,
\'comment_author\' => $comment_author,
\'comment_author_email\' => $comment_email,
\'comment_content\' => $comment_body,
\'comment_type\' => \'\',
\'comment_parent\' => 0,
\'user_id\' => 1,
\'comment_author_IP\' => \'127.0.0.1\',
\'comment_agent\' => \'Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10 (.NET CLR 3.5.30729)\',
\'comment_date\' => $time,
\'comment_approved\' => 1,
);
wp_insert_comment($data);
Update:从…起
this page 它像处理所有这些一样接合,但不剥离HTML/PHP标记;纯粹从安全角度来看,这本身是否值得剥离?