Unfortunately, it seems a bit awkward to differentiate between empty and NULL strings. That's something to be careful of.
Also, I really think this should be included in the blog post, even if it's simple. Protecting against SQL injection is not optional, so leaving it out only muddies the comparison with more traditional frameworks. Also, there's always going to be someone that copies and pastes it without thinking much about it.
That being said, this is very cool and I hope to see more development and exploration in this area.