It was a bad move not include protection against SQL injection to begin with. I was thinking about keeping it as simple as possible and just show a simplified example. But I think this was a bad thing to do so I have updated the example so it now uses postgres_escape.
And yes, this approach should only be used for very simple APIs. If you're building something bigger, use a framework.