I wished there was a new PHP syntax that would escape strings before substituting them. Like this:
escaped_query="INSERT INTO t (a,b) VALUES ('$!some','$!thing');
The "!" means "escape this variable".
That would be the easiest way to create queries with escaped parameters.