Original Post
I need to create a PHP function that does the same thing as mysql_real_escape_string. The reason being that I need to use this function more than I actually need to connect to the database. According to the PHP Manual Page, mysql_real_escape_string escapes the following characters: \x00, \n, \r, \, ', " and \x1a. Is this an equivalent function? function my_real_escape_string($value) { $search = array("\x00", "\n", "\r", "\\", "'", "\"", "\x1a"); $replace = array("\\x00", "\\n", "\\r", "\\\\" ,"\'", "\\\"", "\\\x1a"); return str_replace($search, $replace, $value); } Or is there a reason this isn't safe, etc?