Use params in sql query

Hi @andreiz, thank you for the heads up! There was a hiccup during the refactoring, this issue has been already fixed and will be deployed with the very next deploy - probably on Monday.

Sorry for the inconvenience!