Firstly, as a PHP rule, you don’t need to echo
a variable when doing a string concatenation.
Secondly, you need to prepare your query when adding a variable inside.
So your query would become like this:
$prepared = $wpdb->prepare(
"SELECT meta_value FROM wp_woocommerce_order_itemmeta WHERE meta_key = '_wc_checkout_add_on_label' AND order_item_id = %s",
$orderID
);
$size = $wpdb->get_results( $prepared );