Recommended Free Tools
Call session_start() before output, confirm the session contains your app’s authenticated-state marker, then escape the stored name when you print it:
<?php
session_start();
if (isset($_SESSION['logged_in']) && $_SESSION['logged_in'] === true) {
echo 'Welcome, ' . htmlspecialchars(
$_SESSION['username'] ?? '',
ENT_QUOTES | ENT_SUBSTITUTE,
'UTF-8'
);
} else {
echo 'Please log in.';
}
?>
logged_in and username are example session keys. Replace them with the exact keys your login handler sets. PHP’s $_SESSION documentation shows the same general pattern: set a login marker, check it on a protected page, and escape displayed user data.
As an Amazon Associate I earn from qualifying purchases.
Set the session values after successful login
After verifying credentials, the login handler must store the information the later page will display. For example, it might set $_SESSION['logged_in'] to true and $_SESSION['username'] to a display name. The output page must use those same keys; PHP does not create a username value automatically.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesRegenerate the session ID when authentication succeeds and before storing authenticated session information. PHP’s session security guidance recommends regenerating IDs when privileges are elevated, such as after authenticating.
#1 Best Overall
Start the session before reading it or sending output
Call session_start() on every request that needs the session, before accessing $_SESSION. It resumes the session and restores its saved data. For cookie-based sessions, PHP requires it to run before output is sent, because session handling may need to send HTTP headers. Put it at the top of the PHP file, before HTML, whitespace, or an echoed message. See the session_start() manual page.
Check authentication, not just whether a name exists
A name in the session is not, by itself, proof that the current visitor is authorized. Check the authenticated-state marker set by your login code, and perform the appropriate authorization check on every protected page. The example uses a strict comparison with true so a missing or differently typed value does not pass as authenticated.
Rank #2
Escape the name where it is rendered
htmlspecialchars() converts special characters so a username inserted into HTML text is displayed as text rather than interpreted as markup. The example specifies UTF-8 and handles quotes and invalid sequences. Escape at the point of output rather than changing the stored value. HTML escaping is for HTML contexts; it is not a universal encoder for JavaScript, CSS, URLs, or other contexts. See PHP’s htmlspecialchars() reference.
Troubleshoot missing or unexpected session output
- Blank name or undefined array key: Check the successful-login code for the exact
$_SESSIONassignment and make sure the display code uses the same key. - Session is empty on the next page: Confirm both requests use the same session configuration and browser cookie, and that the reading page calls
session_start(). - “Headers already sent” warning: Move
session_start()before all HTML, whitespace, and other output. - Unexpected HTML appears in the name: Escape the value when rendering it with
htmlspecialchars(); do not rely on escaping performed when saving it.
Release the session lock when a request only needs to read
With PHP’s default file-based session handler, a request can hold a lock on the session while it is open, which may make concurrent requests wait. If the request only needs to read session data, session_start(['read_and_close' => true]) can avoid keeping that lock open. If the request needs to write, make its updates first and close the session when appropriate. The basic session usage documentation describes the session workflow and default handler behavior.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




