>Is it possible, accidentally or on purpose, to pass a
>wildcard to this function that would have the effect
>of deleting many or all rows (shortname is a unique,
>non-null field)?
>
>[code snipped]
Definitely. Have a look at PDO and prepared statements.