$mysqli = new mysqli('localhost', 'root', 'password', 'database');
if (mysqli_connect_errno()) {
printf("Connect failed: %s\n", mysqli_connect_error());
exit();
}
$query = "SELECT COUNT * user_details WHERE user_name=?";
$stmt = $mysqli->stmt_init();
if(!$stmt->prepare($query)){
print "Failed to prepare statement\n";
}else{
$stmt->bind_param("s", $username);
$stmt->execute();
$result = $stmt->get_result();
var_dump($result);
}
$stmt->close();
$mysqli->close();
Don't forget to select database.
Code hasn't been tested yet.
Data binding was used you can find more about it here: Mysql injection