Here is a security function that will stop SQL Injection from being made, if your using MYSQL too store Usernames, Passwords, API Keys and data like this!
Jesus christ, get rid of that incredibly outdated shit, use mysql prepared statements and use htmlspecialchars when outputting to the page if you're not using a framework that does that for you. I am assuming you noticed "someone" was able to make it output javascript to the admin account of your website ^^