Protip:
1. Use a not-100%-polished website design that inspires trust, or
2. Ask your visitor to execute random shell code from the internet, or
3. Place a non-trivial redirect in that code that makes it impossible to examine what exactly is being run on your system.
But, please, for the sake of all that is holy, do not do all three at once.
(Yes, I know there is a "Source Code" link, but that's not directly what's getting run, is it?)