It's unlikely that any SQL injection exists in your module because of the way Blesta is designed, so long as you're not running your own queries outside of the record component. Still, security is a legitimate concern and modules could be vulnerable to XSS or other vulnerabilities. I don't think @AnthonyL is trying to attack you, and it doesn't mean that you've done anything wrong.