Is the code in Q2a secure from SQL injections?

Yes, throughout. All parameters to SQL queries are substituted for # or $ in the queries you see in the code, and this substitution takes care of escaping.
Could You point me / us to an article or good source about that ? Seems to be good to know about when working with foreign scripts.