How ‘secure’ are loops?

This loop looks pretty sure to me. You aren’t exposing any raw SQL anywhere, so injection attacks shouldn’t happen.

Hata!: SQLSTATE[HY000] [1045] Access denied for user 'divattrend_liink'@'localhost' (using password: YES)