In Haskell, I'd have a module, Database, that held all my db code. That module would export functions something like
query :: Query -> DBResult update :: Query -> DBAction -> DBResult
(read those as "query is a function that takes a Query and returns a DBResult.")
In the rest of my program, those functions would be the only way to talk to the database. There's your guarantee.
Could I, rather than using my nice database module, instead drop into IO and write code to do something vicious? Surely. But now we've moved beyond bugs and into active malice.
> "Again, so this cannot be done in a dynamic language? If it can be done, why bring them up?"
It's harder. With duck typing, if it looks like a Query it is a Query, no? Even if it drops your table. I'm no expert on dynamic languages, and I'd believe that there are sophisticated object hierarchies that can do these things (at runtime...), but the original article is empirical evidence that real projects get this wrong.
Really, though, try a language with a modern type system and see for yourself. I know we Haskell users sound like zealots, but the difference between the Java and Haskell type systems truly is night and day.