Is using filter_input() or any similar validation/sanitation function overkill when using PDO prepared statements:
$sql = "SELECT count(*) FROM players_test WHERE email = :value";
$stmt = $pdo->prepare($sql);
$value = filter_input(INPUT_POST, 'signupEmail', FILTER_SANITIZE_STRING);
$stmt->bindParam(':value', $value, PDO::PARAM_STR);
$stmt->execute();
What would be a reasonable approach to handle stings and integers?