Is there any concern that limiting JavaScript's functionality could cause unexpected behavior? E.g., your credit card is charged upon checkout but next part of payment flow isn't triggered and your order isn't actually placed. Or, some DDOS protector thinks you are the same agent as everyone else using a similarly restricted config.