Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quotes and symbols in a name stored in a database usually need no special treatment when PHP reads the value: fetch it as you would any other column. If you use that name in a SQL query, bind it as a parameter rather than adding slashes or removing characters. If it looks wrong only on a web page, escape it for HTML output with htmlspecialchars().

First identify where the quotes or symbols occur

There are two different cases that are easy to confuse:

  • Stored value: A column such as people.name contains text like O'Brien. The apostrophe is part of the data. Fetch it normally.
  • Identifier: The table or column name itself contains a special character or reserved word. That name is part of the SQL statement’s structure, and its quoting rules depend on the database engine.

Also distinguish a query problem from a display problem: a value can be retrieved correctly in PHP yet appear incorrectly when rendered in a page.

Fetch a stored name and bind it when searching

With PDO, prepare the SQL, pass the search text separately, and then fetch the row. For an HTML page served as UTF-8, escape the retrieved value when you display it:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
$stmt = $pdo->prepare('SELECT id, name FROM people WHERE name = :name');
$stmt->execute(['name' => $searchName]);
$row = $stmt->fetch(PDO::FETCH_ASSOC);

if ($row !== false) {
    echo htmlspecialchars($row['name'], ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8');
}

This assumes $pdo is an established PDO connection, people.name is a data column, and the output is HTML encoded as UTF-8. The placeholder :name is unquoted in the SQL template; the actual value is supplied separately. PDO documents that parameter markers represent complete data literals and recommends prepared statements with bound parameters rather than manually quoting values: PDO::prepare.

PDOStatement::fetch() retrieves the next row from the result set; the form of the returned row depends on the fetch mode. See PDOStatement::fetch.

Do not strip or manually escape punctuation in values

Apostrophes, quotation marks, and other punctuation inside a stored value are data, not SQL instructions. When using a value in a query, binding keeps it separate from the SQL statement so those characters do not change the statement’s structure. MySQL’s prepared-statement documentation explains that parameter values may contain quote and delimiter characters without requiring them to be escaped for SQL: MySQL 8.4: PREPARE statement.

Avoid building a query by concatenating user input or relying on addslashes() or PDO::quote() as a substitute for parameter binding. PHP notes that PDO::quote() is driver-dependent and recommends PDO::prepare() with bound parameters instead: PDO::quote.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If the special characters are in a table or column name

Placeholders bind data values; they cannot stand for identifiers such as table or column names, or for arbitrary SQL fragments. PHP states this limitation in its PDO::prepare documentation. If an identifier must vary, select it from a fixed allowlist of identifiers your application supports; do not treat arbitrary input as a bound identifier.

Identifier delimiters vary by database, so use the syntax for your actual engine and version rather than a supposed universal PHP escaping method:

  • MySQL 8.4: Identifiers are quoted with backticks; an embedded backtick is doubled. The ANSI_QUOTES SQL mode changes how double quotes are interpreted. See the MySQL 8.4 identifier rules.
  • PostgreSQL 15: Delimited identifiers use double quotes, and an embedded double quote is doubled. PostgreSQL string constants use single quotes, with an embedded apostrophe doubled. See PostgreSQL 15 lexical structure.

These rules are database-specific: quoting a MySQL identifier as if it were PostgreSQL syntax, or vice versa, is not a portable solution.

Keep retrieval separate from HTML output

SQL parameter binding protects the query structure; it does not encode a value for display. When inserting text into HTML, use htmlspecialchars() with the appropriate flags and character encoding, as in the example above. PHP documents that function’s conversion of special HTML characters at htmlspecialchars(). For JavaScript, URLs, CSS, or another destination, use output handling appropriate to that context rather than assuming HTML escaping covers it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Trace the failure to the right stage

  1. Identify the database engine and version. Check the SQL template and whether the special text is a value or an identifier.
  2. Inspect the fetched PHP value before rendering. Check the actual string without first altering it, and verify the query returns the expected row.
  3. Check the fetch behavior. Confirm the result and fetch mode; PDO’s fetch() returns the next row from the result set.
  4. If PHP has the right text but the page does not, check database and response character encodings, then apply output-context escaping for HTML.
  5. If the query errors or finds no match, bind the value instead of adding slashes, stripping quote characters, or interpolating it into SQL.

Without the actual query, fetch code, database engine, sample value, and observed error, it is not possible to pinpoint which stage is failing. Those details distinguish a SQL error, a missing match, an altered PHP string, and a display issue.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.