PDO Prepared Statements with multiple conditions in where clause

Viewed 1741

If I'm using PDO prepared statements, and I have a query like this:

SELECT cat_name, cat_id_PK, cat_amount
FROM categories
WHERE month=? AND is_recurring = '0'
ORDER BY cat_name ASC;

$results->bindValue(1, $cur_month);

Should I also be binding the value of the is_recurring clause? The '0' is hard-coded in, and I don't think it would leave me vulnerable to SQL injection, but I wanted to ask to be sure. I noticed in a tutorial I was looking at that they did bind the value even though it wasn't a variable being passed, which made me wonder if I was doing it right.

2 Answers
Related