You should always remember that sql is pretty useless to learn about since most sites aren't vulnrable to sql anymore. thedatabase management of an sql database is done with php the actual database is a sql database, but websites interact with databases using php. php coukd mean the site is vulnerable to sqli, but that is only an issue if proper measures aren't put into place, it can be. you don't need php in the url for it to be php it's the code that runs the actual site,it manages databases, actions etc. php runs the whole backend of a site. you could try to put an apostrophe in the url or password input to see if there is an error. if the domain name isnt vulnerable to sqli, that means every file path of the domain probably isn't vulnerable because they are aware of sqli. you should also see what fourm script the site is running. for example, if they are running mybb, there could be a vuln in mybb itself or one of the plugins it uses. another thing you should be able to do is identify if a site even uses sql. for example, a site like roblox may use sql because it has accounts and inorder to have accounts php is used. another way would be to look and see if the site has for example id=1 add a ' after it. if the site is vulnerable you'll see a sql error. but no one cares about sqli it is pretty much dead so telling you this is pointless.