Are PDO prepared statements sufficient to prevent SQL injection? Are PDO prepared statements sufficient to prevent SQL injection? php php