PDO kullanın otomatik escape yapar

$sth = $db ->prepare('SELECT * FROM table WHERE id = :id');
$sth->bindParam(':id', $value);