First off, I need to explain that I come from a Java programming background. However, I now write PHP as my main programming language in my current position. I received a lot of security training in my past job working in Java.
One of the things that was drilled into us was to rely on the proper use of database prepared statements (see
http://en.wikipedia.org/wiki/Prepared_statement) to guard against SQL injection (see
https://www.owasp.org/index.php/Preventing_SQL_Injection_in_Java#Prepared_Statements).
There are some of us that prefer to code the SQL directly instead of using an ORM tool because it allows better control over the SQL syntax.
I'm kind of surprised that the MODx documentation encourages programmers to manually code input escaping, instead of relying on the database driver to do the work for you by using prepared statements (see
http://rtfm.modx.com/display/MODx096/escape). Instead, I would encourage the MODx community to offer examples like the following:
$stmt = $modx->prepare("select * from my_table where key = :recordKey");
$stmt->bindParam(':recordKey', $key );
$stmt->execute();
$rows = $stmt->fetchAll(\PDO::FETCH_CLASS);
Anyone agree? What are your thoughts?