Every other section of this chapter taught you to make PHP do something; this one is about stopping it doing something an attacker wants. The two are the same code from opposite ends: the form that greets a customer greets an attacker too, and the query that finds one order will dump every order if it is built by pasting strings together. Security is a set of habits applied wherever data crosses a boundary.
Each class of vulnerability is shown twice: a deliberately weak script that a real attack defeats, run against 127.0.0.1 with its genuine output, then the fix. Every weak listing is labeled for learning or VULNERABLE and exists only to be attacked; never deploy one. Where an earlier section did the work this one points back (prepared statements in Databases with PDO, sessions in Sessions and Uploads, escaping in Subsection 4.6.11, headers in Caching and Headers and Complete .htaccess Recipes). The frame is the OWASP Top 10, 2025 edition.