Preventive measures of SQL inject injection
Code level
Strict escape and filtering of input
Use parameterization (Parameterized Query or Parameterized Statement)
Http;//www.w3school.com.cn/php/func_mysql_real_escape_string.asp.
Website level
Enable an anti-SQL Inject injection policy (or similar protection system) through a WAF device
Cloud protection (360 website guard, Ali cloud shield, etc.)