I’m using parse_str to get a raw value from a URL (which is obviously entered by the user), and I’m wondering if there’s anything I should to to make it safe before I use it (i.e. convert special characters like ‘<‘).
I noticed that the function does remove some characters, but I couldn’t find the specifics anywhere.
Thanks.
You can use htmlentities() and then parse_str() or parse_url() function