Security shouldn't be offered as an ad-on. Most clients expect you as developer to know what's best practice.
It is also your responsibility to comply with local/country and international laws.
I reckon the only time it might be allowed to allow certain exploits/unwanted behavior is in a restricted controlled environment.