No! No and no. If you are already using prepared statements, MySQL should see the value, not some escaped version. If you add mysql_real_escape_stringto the line and make this value for the prepared statement, you just ruined it, for example, quotes are doubled!
, , - , . strip_tags html- > raw (format), . , rtrim(ltrim - -.