prepare("INSERT INTO students (first_name, last_name, student_id) VALUES (?, ?, ?)"); $stmt->bind_param('sss', $_POST['first_name'], $_POST['last_name'], $_POST['student_id']); $stmt->execute(); $stmt->close(); //test if there was a query error if($stmt){ //success echo "Success! Student added to database!"; }else{ //failure die("Database query failed. " . mysqli_error($connection)); } ?> SQL Injection