All tools

SQL Query Parameter Placeholder Counter

Code

Count and list positional (?, $1) and named (:name, @name) parameter placeholders in a SQL query, flagging mixed styles and numbered-sequence gaps or duplicates

Paste a SQL query and get back every positional (? or $1, $2) and named (:name or @name) parameter placeholder it contains, a count per style, and two specific checks: whether the query mixes placeholder styles (a common sign of copy-pasted code written for two different drivers) and whether a numbered sequence like $1, $2, $3 has a gap or a duplicate, both of which usually mean a parameter-count mismatch waiting to happen at bind time. String literals and line/block comments are skipped during scanning, so a placeholder-looking character inside either is never miscounted. This is a pre-flight sanity check before binding parameters, not a SQL parser or validator against a live schema.

sqlplaceholderparameterslintprepared-statement

How to use SQL Query Parameter Placeholder Counter

  • 1.Paste a parameterized SQL query, or try one of the sample queries to see the output shape.
  • 2.Check the per-style counts and the mixed-style warning to confirm the query sticks to one placeholder convention.
  • 3.For numbered placeholders, review any reported gap or duplicate before binding parameters, since both usually indicate a mistake in the parameter list.

Frequently asked questions

Does this validate the SQL query itself?
No, it only scans for parameter placeholders; it doesn't parse SQL grammar, check table/column references, or execute anything against a database.
Why wasn't a placeholder-looking character inside a string counted?
Characters inside single/double-quoted string literals and line (--) or block (/* */) comments are intentionally skipped, since they aren't real bind parameters.
Does it handle Postgres's :: type-cast operator or MySQL's @@ system variables?
Yes, both are recognized and excluded so they're never mistaken for a :name or @name named placeholder.
What about Postgres dollar-quoted strings like $...$?
Those aren't specially recognized, so a numbered-placeholder-looking pattern inside one could, in rare cases, be miscounted. This is a known limitation.

Use via API, SDK, or MCP

cURL# Free: 1,000 req/day · Pro: 10,000 req/day
curl -X POST https://api.utilix.tech/v1/tools/sql-placeholder-counter \
  -H "Authorization: Bearer utx_live_..." \
  -H "Content-Type: application/json" \
  -d '{"sql":"SELECT * FROM users WHERE id = ? AND age > $1"}'

Get an API key from your dashboard · Full API docs →