Our library fails to protect against SQLi with some charsets. E.g. with GBK, the \ can be "eaten" up with bytes such as \xbf\x27. It might be worth documenting that it's best to keep the connection as utf-8?