MODx will not support mysqli; Revolution supports MySQL via the PDO_mysql driver or via xPDO’s PDO emulation code which uses the mysql extension.
Just a nagging question... the database API’s do not make use of mysqli (I understand this is planned for Revolution), and use of the db->query() method is discouraged in favor of structuring queries using the db->select() method (or similar): http://wiki.modxcms.com/index.php/API:DBAPI
The DBAPI does nothing to help prevent sql-injection or increase query speed. They are convenience only. PDO (and xPDO) and it’s prepared statements will address this. You still need to make sure you cleanse any user-input you send to the DBAPI functions.
So, are the fundamental db queries preparing statements to help avoid sql-injection and increase query speed? Is there any data-filtering going on inside the MODx db api internals? I’ve gotten burned by sql-injection attacks, so I really want to prepare my queries and filter data whenever possible.
As secure as the code you write with it, same as if you were using the mysql or mysqli extension directly.
How secure is the MODx database API? Thanks for your thoughts.

The mysqli extension allows you to access the functionality provided by MySQL 4.1 and above.
it would be nice if the DBAPI had a safeguard option. When a tool is available for noobies, like an API, it would be nice if it helped prevent security issues.
PDO’s support of prepared statements (which is btw what mysqli provides that mysql doesn’t) is what simplifies coding for database developers, allowing them to focus on logic rather than cleansing user input. And xPDO’s object validation adds an additional layer of protection, as well.That sounds great. With MODx I need to watch what I ask for since it might already be available

You only need rewrite rules to make a custom friendly URL interface to a single MODx document (which is technically a View Controller btw) which turns extra parameters (beyond the modx q= param) into additional url segments. This can be genericized to make this kind of thing easy to do with any particular document that has a script on it that works this way.
dev_cw, I’ll keep you (and the community posted) with my CRUD project. I need to develop access for a project I’m working on. The big nut to crack I figured out and posted the details in this thread (namely reading unique keys from url segments):
http://modxcms.com/forums/index.php/topic,31477.msg193727.html
To integrate with MODx, you’d need to do an Apache RewriteRule, but that’s not so bad... I’ll be writing a Module with some associated Snippets to handle access to external databases or custom tables in an MVC fashion. I haven’t seen anything out there like it...
I spoke with some folks about integrating something like Code Igniter into MODx, but after working with CI’s scaffolding, I realize it’s not immediately usable in production because it’s not secure (the CI folks recommend deleting the scaffolding access as soon as you have data in... it’s meant only as a dev tool). CakePHP and Symfony were just nasty steep learning curves, but I haven’t come across any easy way to get CRUD access to database tables, and certainly nothing that has been ported over to MODx. So... stay tuned. I’ll definitely be making some more tutorial videos about this when the time comes. If anyone has something already built, then please, let me know... I tend to enjoy reinventing the wheel, but it’s not always time-efficient.Again, xPDO was created after my horrible experiences with existing CRUD systems, including Propel and Doctrine (both of which have been integrated into Symfony to some extent). I think once more people understand what it provides, i.e. a jumpstart tool for the M in MVC, and that MODx is a great adaptation of the Views and Controllers already, we’ll see some great custom components appear on the scene.
I have tons of snippets that provide customized form access to manipulating custom data tables in MODx