I would say at this level of understanding, having to learn PDO, prepared statements and parameterised queries is a lot to take on but you're right - as soon as you're comfortable about how to retrieve a value and store it in the database, learn PDO, prepared statements and parameterised queries...