I install PHP on my server (yeah I know) to run some PHP based web based software. By default PHP is configured in a very insecure manner. You would think with all the security problems that they would ship it with a set of secure defaults.
We are talking about an ini file. This isn't rocket science.
However they will now be aware that said feature is insecure and should know the consequences of enabling it.