Explicitely check the return value of PDOStatement::execute()
PHP apparently does not always throw an Exception when a statement
could not be executed successfully. An example of this is:
$sql = "SELECT ?";
$statement = WCF::getDB()->prepareStatement($sql);
$statement->execute([ 1, 2 ]); // returns false
This code is erroneous, as we try to send more parameters than there
are placeholders in the query. Thus execute() properly returns false,
but it does not throw an Exception.
Interestingly enough the reverse case properly throws: Sending less
parameters than placeholders.