im not a big fan of sql real escape...we know that the var should not have any sql..
I find it's useful for letting characters such as ' or " be entered into comment fields or in CMS backend without risk of terminating the SQL command.