A SQL query assembled with format! interpolates values into the statement and risks injection.
Build queries with bound parameters instead of format!; never interpolate values into SQL text.