Sometimes one has to host an application and has no control over the details of how that application is developed or configured related to parameterized SQL queries.
Yes, those are needed too. And static analysis and dynamic analysis, etc.
Despite all of that we just found a SQL injection that existed for years somehow. Luckily the WAF blocked attempts to exploit it until we could issue a fix.