PHP新手求助:Undefined variable: stmt及bind_param空对象调用致命错误
Fixing "Undefined variable: stmt" and "Call to a member function bind_param() on null" in Your PHP Code
Hey there! Let's break down what's going wrong with your code and get it working smoothly.
The Core Issue Causing Your Errors
This is a classic variable name typo—super easy to miss when you're just starting out:
- You stored your prepared statement in the
$statementvariable with this line:$statement = $conn->prepare("SELECT * FROM data WHERE username = ? AND password = ?"); - But every subsequent operation uses
$stmt(like$stmt->bind_param(...)), which was never defined. Since$stmtisnull, trying to call methods on it throws that fatal error, and the "undefined variable" notice is just the first clue pointing to this mismatch.
Bonus Fixes to Avoid Future Headaches
Once you fix the variable name, there are a few more small issues that will trip you up:
- The
fetch()method doesn't take a parameter—you don't need to pass$statementto it. - You're using
SELECT *but only binding$usernameand$passwordwithbind_result(), yet you try to access$nameand$agelater. You either need to bind all columns returned bySELECT *in exact order, or better yet, explicitly list the columns you need in your query to avoid confusion. - Storing plain-text passwords is a massive security risk—always use PHP's built-in
password_hash()andpassword_verify()functions instead of storing or comparing raw passwords.
Corrected Code with Explanations
Here's the fixed version with comments walking you through the changes:
<?php require "conn.php"; // Safely get POST data (prevents errors if fields are missing) $username = $_POST["username"] ?? ''; $password = $_POST["password"] ?? ''; // Explicitly list columns instead of SELECT * for clarity $statement = $conn->prepare("SELECT username, password, name, age FROM data WHERE username = ?"); if (!$statement) { // Add error checking to catch query syntax issues die("Prepare failed: " . $conn->error); } // Use the same variable name ($statement) everywhere $statement->bind_param('s', $username); $statement->execute(); // Bind all columns you selected, in the same order as the query $statement->bind_result($dbUsername, $dbPassword, $dbName, $dbAge); $statement->store_result(); $response = array(); $response["success"] = false; // Fetch doesn't require any parameters while($statement->fetch()){ // Verify password securely (assuming you stored hashed passwords) if (password_verify($password, $dbPassword)) { $response["success"] = true; $response["name"] = $dbName; $response["age"] = $dbAge; $response["username"] = $dbUsername; // Never return passwords in your response! // $response["password"] = $dbPassword; } } echo json_encode($response); ?>
Quick Tips for New PHP Devs
- Always double-check variable names—typos are one of the most common beginner bugs!
- Add error checking for database operations (like
prepare()) to quickly spot issues with your query or connection. - Prioritize security from day one—never skip password hashing, sanitize user input, and avoid returning sensitive data in responses.
内容的提问来源于stack exchange,提问作者kara
相关产品推荐
相关产品推荐

