Who needs prepared statements and parameterised queries when you can just roll your own string escaping mechanism?