"constructing strings of code...which after being constructed have to be parsed for every single query?"
I don't know about MySQL, but my database caches compiled queries.
"Things like SQL injection attacks simply should not exist."
They don't exist, if you don't construct SQL queries by concatenating strings and variables.
Meanwhile, all the cool kids are talking about getting rid of procedural code in favor of declarative DSLs...