SDK: Awesome, thanks, problem 1 solved.
problem 2, how can I prevent flooding, and any sort of injection? I have already found str_replace to prevent commas, but is there anything else I need to worry about?