Looks vulnerable to SQL injection attacks. (https://fortran.io/static/model.html)
Generally, it is recommended that you create a prepared statement entirely from static SQL string(s) (no user input) and then bind parameters into it, such that there is no possibility for any user input to be parsed as SQL:
This is quite frankly nonsense. You have released the software to the wider world it is your responsibility to make sure it is decent. Just because you have released it for free doesn't suddenly mean you can avoid criticism.
SQL injection is such a basic thing to check there is really no excuse.