These can often detect and block common patterns like UNION ALL SELECT before they reach your server.

Breaks out of the intended data field in a SQL query.

This is the gold standard. It treats user input as literal text, not executable code [6].

Appends a new set of results to the original query [2, 5].