This project is insecure by design, since its goal is to assist with teaching security concepts: such as cross-site scripting (XSS) and SQL injection vulnerabilities.
If you have any suggestions, feel free to open up an issue on GitHub: https://github.com/hayesall/bottle-breaker/issues
Vulnerabilities will probably not be fixed, but suggestions may be incorporated if they are interesting (e.g.: something that still involves making cross-site scripting possible, but slightly more difficult to exploit).