SQLi is best handled using the database's native escaping routines and not just relying on addslashes() -- there is actually a way to circumvent addslashes from what I remember. Filtering is probably a good practice as well. To avoid escaping, you could just use PDO and prepared statements which handles the escaping for you automagically as well.
I'm finding the only constant in software development is change it self.
If you could be bothered to read my damn post, it'd be clear that you don't have to reply. What are you, dumber then a flat rock? I'm a doctor Jim, not a blasted librarian.
This blanket smells like ham