" SET firstname = :firstname, lastname = :lastname, email = :email {$password_set} WHERE id = :id"; // prepare the query $stmt = $this->conn->prepare($query); // sanitize $this->firstname=htmlspecialchars(strip_tags($this->firstname)); $this->lastname=htmlspecialchars(strip_...