in reply to Re^2: is this script secured enough from internet attacks
in thread is this script secured enough from internet attacks

Is there something wrong with my personal preference?

Yes. You said you would add a "&" to $db->db_cursor() if it was your own module, but it's impossible to do so.