Filtering user-supplied data against a strict allow-list.
Explain how to from tools like this.
Automated SQLi tools like V10 succeed only when applications have concatenated into SQL queries. Stop that, and the tool becomes useless.