Stored procedures and ORMs won't save you from SQL injection
troyhunt.com
troyhunt.com
If you do it this way you avoid the string concatenation that enables sql injection + you don't need any table permissions just execute permission on the proc:
ALTER PROCEDURE dbo.SearchWidgets
@SearchTerm VARCHAR(50)
AS
BEGIN
DECLARE @filter VARCHAR(52)
SELECT @filter = '%' + @SearchTerm + '%'
SELECT Id, Name FROM dbo.Widget WHERE Name LIKE @filter
END