I'm curious if this is truly a 'security' concern, or more like a hackability issue. Though I could enter that string into the page myself, I can't actually start running scripts on the page or anything, can I?
Really, this doesn't seem any more 'dangerous' than opening the web-inspector and changing the CSS to hide.
Do you agree?
(It may sound like I'm trying to be an ass, but I am actually curious).