Yet one more thing developers have to worry about, as if the list wasn't long enough already. The developer world is still full of people creating sql injection attacks, I think you may be raising the bar to well beyond what is practical.
This just means that you need to add that script kiddie scenario to your threat model and prioritize it accordingly.
At one place I worked, our commercial (wordpress) site got hacked and defaced by some Turkish outfit. The devs at our company reverted the site, and were joking about the hackers just being script kiddies. They didn't seem to understand my point of "... but we were hacked by those script kiddies, why are we laughing?"