I cannot imagine work with SQL without query builder, which introduces type checks and conversions, and escapes strings when needed. ORM is an optional thing, but it is nice to have some layer that maps rows into structs and vice-versa. With dynamically typed scripts it doesn't matter: in any case you would get a hashtable (the only difference is a syntax used), but with compiled language and static typing I feel some uneasiness when using slow hash table mapping instead of blazingly fast struct field access. And the tooling can help to declare that structs statically.
Nobody has advocated writing "raw SQL with raw strings" in years.
The valid way of using Raw SQL is using prepared statements and parametrized queries.
This method will protect you from SQL injection, will handle most issues with type/conversions and the queries are cacheable, so it's fast too.
Parametrization is handled by the database itself (not the specific driver), so it is battle tested.
https://stackoverflow.com/questions/8263371/how-can-prepared...
It is an overstatement. Every time I look into some random PHP code I see there raw SQL with raw strings. Maybe it is just me being "lucky"?
By the way, the thread starter comment was mentioned it, I got phrase from it.