Security is not a feature you bolt on at the end. Here is the checklist we run through on every PHP project before launch.
Always use PDO prepared statements to prevent SQL injection...
Never store plain-text passwords. Use password_hash() with bcrypt or argon2...