Here's a good one that tried to sneak past in an install file as part of the module's installation procedure...
Need I say more? The title of this page says it all.
A recent application was decline basically because Drupal's database API was just non-existent/not used/badly used. This was pointed out to the applicant and asked to read up on how to get things done properly using Drupal's APIs.
On the second attempt this is an example of swinging just the wrong way and "not getting it"...
This cracker came in recently, can you spot the difference? Which is right and which is wrong?
Got it yet? You may have easily spotted the first one was wrong but did you get why it's wrong? It's bad on more levels than you may at first think.