Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Query the category records, then create an HTML <select> with one <option> for each row. Submit each category’s database ID as the option value, show its name as the label, and escape both values before writing them into HTML.
Build the dropdown with PDO
This example assumes a categories table with id and name columns, and an existing PDO connection in $pdo. Change the table and column names to match your schema.
<?php
$stmt = $pdo->query('SELECT id, name FROM categories ORDER BY name');
$categories = $stmt->fetchAll(PDO::FETCH_ASSOC);
?>
<label for="category">Category</label>
<select name="category_id" id="category" required>
<option value="">Choose a category</option>
<?php foreach ($categories as $category): ?>
<option value="<?= htmlspecialchars((string) $category['id'], ENT_QUOTES, 'UTF-8') ?>">
<?= htmlspecialchars($category['name'], ENT_QUOTES, 'UTF-8') ?>
</option>
<?php endforeach; ?>
</select>
PDO::query() fits this fixed SQL statement because it has no placeholders or user-provided filter. If the query depends on user input, prepare it and bind the input as a parameter rather than inserting that input into the SQL string. See PHP’s PDO::prepare documentation and PDO::query documentation.
fetchAll(PDO::FETCH_ASSOC) returns the remaining rows as an array keyed by column names. If the query returns no rows, the array is empty and the loop produces no category options beyond the prompt. PHP notes that fetchAll() can consume substantial resources for large result sets; for unusually large category lists, limit or redesign the selection. PHP documents fetchAll() behavior and considerations.
#1 Best Overall
Keep SQL handling and HTML output safe
These are separate jobs: bind user-provided values when they enter SQL, then encode database values when they enter HTML. A prepared statement does not make later HTML output safe.
- Escape at output. The category ID is placed in a quoted HTML attribute, while the name is placed in HTML text.
htmlspecialchars()converts special characters to HTML entities; specifyingUTF-8makes the intended encoding explicit. PHP’s htmlspecialchars() documentation. - Submit an identifier, not a label. Use the database key for the option’s
value; treat the visible category name as presentation text. Validate the submitted ID on the server against the current records and the user’s permissions when processing the form. - Use a label. The
<label for="category">associates a readable name with the select control. The<select>and its<option>elements provide the control and its choices. MDN’s select reference.
Adapt the dropdown to your form
Require a deliberate choice only when needed
The empty prompt option gives users a clear starting point. Keep required only when the form must have a category; remove it if leaving the category unset is valid.
Rank #2
Mark an existing category as selected
When editing a record, compare each category ID with the validated ID stored for that record or supplied by the form. Add the selected attribute to the matching option. Validate the value before using it, and continue escaping the ID and name when outputting them.
Check your database setup
The example expects $pdo to be configured and the relevant database driver to be installed. It does not create the connection or determine your table and column names; those depend on your application’s setup.
Recommended Free Tools
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




