#1 Does not have a way to protect against injection ie real_escape_string()
#1 Does not have a way to protect against injection ie real_escape_string()