Hi! I want to know, a direct SQL query in a php snippet, is it safe or not?
$package_query = $wpdb->prepare(
"
SELECT comment_karma
FROM {$wpdb->prefix}comments
WHERE user_id = %d
AND comment_type = %s
AND comment_content = %s
",
$user_id,
'hp_listing_package',
'Paid package here'
);
$package_karma = $wpdb->get_var( $package_query );