I don't know. If you actually care you can probably ask on the mailing list; it is an open-source project after all.
(This week I read about attacks convincing users to open the dev console and paste Javascript code in there. Users will do anything as long as it harms their account or their computer, it seems.)