OverpayingForAIPricing desk

Code fix · 4 checks · max 600 tokens · benched 2026-09-16

GPT-5.5 vs GPT-5.4 vs GPT-5.4 mini vs GPT-5.4 Nano vs GPT-5.3-Codex on parameterise a sql query in python

OpenAI models side by side on "Parameterise a SQL query in Python": GPT-5.4 Nano scores 10/10; GPT-5.4 Nano is the cheapest answer scoring 8+ at $0.07 per 1,000 runs. Outputs, checks, judge reasons, latency and cost.

The prompt every model received

System

You are a senior engineer. Reply with code only unless asked otherwise.

User

This sqlite3 code is vulnerable to SQL injection. Rewrite it to use a parameterised query with sqlite3's ? placeholder. Return the complete corrected function only.

def find_user(cursor, email):
    query = f"SELECT id, name FROM users WHERE email = '{email}'"
    cursor.execute(query)
    return cursor.fetchone()

Rubric for the judge: Uses execute(sql, (email,)) with a ? placeholder, keeps the same columns and return, no string formatting left.

Side by side

Every cell is one OpenRouter call at temperature 0 with the prompt's token cap and reasoning effort "low" where the model supports it. Cost is usage × the catalogue rate in models.json. Quality is one judge call to anthropic/claude-haiku-4.5 against the prompt's rubric, cached per prompt version.

GPT-5.5

openai/gpt-5.5

10/10
Latency
343ms
Cost
$0.00162
Per 1,000
$1.63

91 in · 39 out · 18 words · checks 3/4

  • contains
  • regex
  • not_contains
  • not_contains
def find_user(cursor, email):
    query = "SELECT id, name FROM users WHERE email = ?"
    cursor.execute(query, (email,))
    return cursor.fetchone()

Judge: The output correctly uses parameterised query with ? placeholder, execute(query, (email,)) syntax, maintains identical columns and return statement, eliminates all string formatting, and provides only the corrected function as requested.

GPT-5.4

openai/gpt-5.4

10/10
Latency
428ms
Cost
$0.00081
Per 1,000
$0.81

91 in · 39 out · 18 words · checks 3/4

  • contains
  • regex
  • not_contains
  • not_contains
def find_user(cursor, email):
    query = "SELECT id, name FROM users WHERE email = ?"
    cursor.execute(query, (email,))
    return cursor.fetchone()

Judge: The output correctly uses parameterised query with ? placeholder, execute(query, (email,)) syntax, maintains identical columns and return statement, eliminates all string formatting, and provides only the corrected function as requested.

GPT-5.4 mini

openai/gpt-5.4-mini

10/10
Latency
416ms
Cost
$0.00030
Per 1,000
$0.30

91 in · 52 out (11 reasoning) · 18 words · checks 3/4

  • contains
  • regex
  • not_contains
  • not_contains
def find_user(cursor, email):
    query = "SELECT id, name FROM users WHERE email = ?"
    cursor.execute(query, (email,))
    return cursor.fetchone()

Judge: The output correctly uses parameterised query with ? placeholder, execute(query, (email,)) syntax, maintains identical columns and return statement, eliminates all string formatting, and provides only the corrected function as requested.

GPT-5.4 Nano

openai/gpt-5.4-nano

10/10
top judge scorecheapest scoring 8+
Latency
658ms
Cost
$7.2e-5
Per 1,000
$0.07

91 in · 43 out · 20 words · checks 3/4

  • contains
  • regex
  • not_contains
  • not_contains
```python
def find_user(cursor, email):
    query = "SELECT id, name FROM users WHERE email = ?"
    cursor.execute(query, (email,))
    return cursor.fetchone()
```

Judge: The output correctly uses parameterised query with ? placeholder, execute(query, (email,)) syntax, maintains identical SELECT columns and return statement, eliminates all string formatting, and provides only the corrected function as requested.

GPT-5.3-Codex

openai/gpt-5.3-codex

10/10
Latency
435ms
Cost
$0.00071
Per 1,000
$0.70

91 in · 39 out · 18 words · checks 3/4

  • contains
  • regex
  • not_contains
  • not_contains
def find_user(cursor, email):
    query = "SELECT id, name FROM users WHERE email = ?"
    cursor.execute(query, (email,))
    return cursor.fetchone()

Judge: The output correctly uses parameterised query with ? placeholder, execute(query, (email,)) syntax, maintains identical columns and return statement, eliminates all string formatting, and provides only the corrected function as requested.

Frequently asked

What does this prompt test?

Code fix: Uses execute(sql, (email,)) with a ? placeholder, keeps the same columns and return, no string formatting left. The deterministic checks are contains, regex, not_contains, not_contains.

Which model should I pick for this task?

If the judge's bar of 8/10 is good enough for you, GPT-5.4 Nano at $0.07 per 1,000 runs. If you need the top score, GPT-5.4 Nano at $0.07 per 1,000 runs.

If our calculators helped you cut down on hidden AI wallet leaks, thanks for using them. A tiny fraction of your savings is what keeps our pricing indexes updated daily.

Not sure which AI is cheapest for your use case? Find out in 30 seconds — no signup required.

AI cost intelligence

Stop overpaying for AI tools

Join the OverpayingForAI list for pricing updates, cheaper alternatives, and practical buying guidance.

Now tracking 50+ AI tools, models, platforms, subscriptions, coding tools, and automation products.

We use your email only for OverpayingForAI updates. Unsubscribe anytime.