Not detecting code with potential for sql injection

Thanks for the quick reply, we just bought SonarQube and really want to be able to built it into our dev process, and start use/trust SonarQube to find issues in our code.

Since this is a new installation of the SonarQube server could there be something wrong with our installation?
We also see other projects (.net 5, web apps) where SQ is not analyzing .cs files. It does analyze .cshtml and so on but not plain .cs files:
image

I already created a ticket on that matter, but now I am wondering if it could be related somehow?
Here’s the related ticket: Not analyzing .cs files - only .cshtml, js, etc