Metaprogramming/reflection would be impossible without treating code as content.
Metaprogramming/reflection would be impossible without treating code as content.
Maximizing utility on a website might look like dropping a user into a root REPL so they can perform arbitrary actions and are unlimited in their capabilities. Maximizing security might look like shutting down the website and all its associated servers. In reality, from a security perspective, we try to achieve a balance between the two by maximizing utility while minimizing security risk.
Personally, I think code as content, reflection, eval, etc move the slider too far in the utility direction. Of course this is a difficult problem to solve because nearly all our systems are built on the idea of code as content, which is also what makes it such a generalized vulnerability class.
The real difference is that you generally have to be in physical proximity to hardware in order to tinker with it, and that puts a very hard constraint on random people mucking with your car. Not so for software, especially in the age of the internet.
If code is data and data is immutable then code is immutable.
I am sure you see the contradiction in objectives.
What you call in-band - I call data. What you call out-of-band - I call code.
What I call metaprogramming is erasing the distinction.