As per title, we should avoid at all cost using non-prepared query and NEVER use them whenever the input come from the user.