On the security front, the SQL blacklist definitely has to go. It's a false sense of security (ex: string concat + dynamic execution gets around it). The suggestion to use a read only user is a good one but even better is to use a read only database (ex: a Postgres replication slave).
Have you checked out JackDB? (http://www.jackdb.com/ full disclosure: I'm the founder) It's a full featured database client that runs entirely in your browser.