传递php变量onclick会出错

Please see the scripts below. Onclick of Add gives an error when a php variable ($var)is used, however it will work with a number - i.e. if the line in index.php:

echo '<button id="1" onclick="company_add(\''.$var.'\');">Add</button>';

Is changed to something like:

echo '<button id="1" onclick="company_add(',57776,');">Add</button>';

What am I missing please?

Index.php:

<html>
<head>
<script type ="text/javascript">
function company_add(company_name) {
$.post('company_add.php', {company_name:company_name}, function(data) {
   if (data == 'success'){
    alert("Cool");
   } else{
       alert(data);
   }
});
}
</script>
<script type="text/javascript" 
src="http://ajax.googleapis.com/ajax/libs/jquery/1.7.2/jquery.min.js">      
</script>

<?php
include 'connect.php'; //Generic connect file
$var = 'Name';

echo '<button id="1" onclick="company_add(\''.$var.'\');">Add</button>  
<br/>';
?>
</body>
</html>

company_add.php:

<?php
include 'connect.php';

function company_exists($company_name) {
return (mysql_result(mysql_query("SELECT COUNT(`company_name`) FROM   
`company` WHERE `company_name` = $company_name"), 0) == 0 ) ? false :    
 true;
 }

function add_company($company_name){
mysql_query("INSERT INTO `company` (`id`, `company_name`) values ('', 
".$company_name.")");
}

$company_name = $_POST['company_name'];

if (company_exists($company_name) === true) {
echo 'Company already added';
} else {
add_company($company_name);
echo 'success';
}
?>

Use that line like this:

echo "<button id='1' onclick='company_add('" . $var . "');'>Add</button>";

In case if you already have commas after and before the value of the $var you should trim it. So use it like this:

$var = ltrim(",", $var);
$var = rtrim(", ", $var);
echo "<button id='1' onclick='company_add('" . $var . "');'>Add</button>";

And for your information yes you can even use a String instead of a Number too.

And UPDATE the functions:

function company_exists($company_name) {
  $company_name = mysql_real_escape_string($company_name);
  $query = "SELECT * FROM company WHERE company_name = '{$company}'";
  $result = mysql_query($query);
  if(mysql_num_rows($result) > 0) {
    return true;
  }else{
    return false;
  }
}

function add_company($company_name){
  $company_name = mysql_real_escape_string($company_name);
  $query = "INSERT INTO company (id, company_name) VALUES ('', '{$company_name}')";
  return mysql_query($query);
}

If you are using id field of that company table as AUTO_INCREMENT then you can leave the id field NAME & VALUE in the INSERT Statement. Like This in the add_company Function:

$query = "INSERT INTO company (company_name) VALUES ('{$company_name}')"