Maybe not a good idea to link a page that runs source code created by random people. Well CSS is very safe, but still.
For example some controlled frameworks can even have CSS only keylogging https://css-tricks.com/css-keylogger/
The correct solution is enable a strict Content Security Policy (CSP) - so even when a user compromises your website with XSS/CSS they cannot extract any data they obtain. Note: this website has not configured a Content Security Policy :(