You are already compromising security — see SQL injection strings and escape strings.
In addition, it is common practice to include other application modules that require (see functions require_once()and require()). It alone is not a security vulnerability, but it does cover all global variables, functions, and classes for this script.
, (. unset()) , , , .
, , . PHP .
EDIT:
, . encapsulation, , .