Use the Hash plugin instead of Array plugin, this works much smoother with json objects.
You don't need to do anything against sql injections, do that in your backend and everything is fine.
Currently C2 grants you everything you need to make a great Login system (Eg Webstorage to save sessions)