It's an interesting idea, but attackers would switch to using javascript. And I don't think it's realistic for typical users to have javascript default off.
Yeah, indeed, this idea is not meant for typical users; only those who have script blockers and the like installed in their browsers. At present, even such security concious users can be deceived with layout and URL masquerades.