The proper YAGNI reply to this would be to use a proper library or work in the right abstraction layer so that you don't have to worry about SQL injection. For instance, Django provides the csrf_token which can be dropped in. That's still less code and secure.