How could someone working in a security context in modern times be using non-parameterized queries? I know the answer is along the lines of "because PHP" but I just can't believe it. This really makes me paranoid regarding other security SaaS.
Is it actively used?
And even then, the PHP documentation was ALWAYS telling people "PLEASE FOR THE LOVE OF EVERYTHING THAT IS HOLY MOVE TO PDO AND STOP USING NON-PARAMETRISED APIs"
But the problem is that with PHP, a LOT of the problems are usually resolved by programmers using the age old "copy pasta from a stackoverflow thread that's 10 years old".
However, I do concede that for someone who's in a security context, it is absolutely narrow minded to allow ANYTHING beyond parametrized queries.