No, please don't. Use quote_identifier for table and column names.
quote is useful when placeholders can't be used, e.g. you're sending the SQL statement to a function that doesn't accept any other arguments and you can't change it; but generally placeholders are easier and cleaner.
In reply to Re^7: DBI do() SQL injection
by choroba
in thread DBI do() SQL injection
by Anonymous Monk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |