String escaping SQL? How is anyone thinking that is still a thing in 2017? The problem has been solved for two decades