# Which is better?

**URL:** <https://forum.kirupa.com/t/which-is-better/200256>\
**Category:** Uncategorized\
**Created:** [September 10, 2006, 7:01pm UTC](https://forum.kirupa.com/t/which-is-better/200256 "2006-09-10T19:01:24Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![raz1](https://avatars.discourse-cdn.com/v4/letter/r/ee7513/32.png) [@raz1](https://forum.kirupa.com/u/raz1)\
**Post date:** [September 10, 2006, 7:01pm UTC](https://forum.kirupa.com/t/which-is-better/200256/1 "2006-09-10T19:01:24Z")

</div>

I have a search form thats going to be searching for information from a database. Thats all fairly simple but my question has to do with preventing SQL Injection…

Should I:  
A) Use javascript so when a user clicks search \<\>!#@$&%).’ all get stripped from the form, then submit the information thats left;  
-or-  
B) Just use PHP to strip\_tags() the value of the form;

Which would be easier? I’m thinking the PHP, but also which would be more efficient?

If I did do PHP, it would prevent SQL Injection right? I’m not a big fan of nerds who have fun with forms… lol
