It depends on how you fulfill your requests:
Formatting through Prepared Statements is done by the server, which, in turn, deactivates your query from any SQL injection. But it has other restrictions, for example, you cannot execute more than one query at a time, and if necessary you cannot provide unacceptable entity names.
Normal query formatting is sanitized for values, and although it provides flexibility in formatting entity names and multiple queries, it does not provide protection against SQL injection.
source share