I know that it deflects SQL Injections. But why use prepared statements, if I can just verify user input myself, before putting it in the string-query?
Pseudo-Code:
//Prone to SQL Injections
String userInput = ...;
String query = "SQL BLABLA" + userInput + "OTHER SQL BLABLA";
//NOT prone to SQL Injections, in my opinion
String userInput = verifyUserInput(...);
String query = "SQL BLABLA" + userInput + "OTHER SQL BLABLA";
...
function verifyUserInput(String userInput){
if userInput is weird: return default input or something
}
I mean, most of the time you need to verify the input anyway.