postComment: "Agreed. I'm still mixed on the issue of placing user-definable raw HTML into pages. The way Wikidot works at the moment (with its AJAX interface) makes it vulnerable whenever it comes to raw HTML in the * and any custom domains. It puts Wikidot in a hard position, to judge if the code is a security threat.\nI could easily create a service… let's say a JS powered plugin for a \"like\" function. An embed code could be <script type=\"text/javascript\" src=\"\"></script> (this is all fictional, btw). Wikidot could go to the site to see if it's legit at that present moment. Once the plugin gets approved, I could easily change it into some rouge code which changes the user's email address and passwords and make it post dozens of spam posts on any forum on any Wikidot site.\nI do think that Twitter, Google and Facebook can be trusted. But it does put Wikidot in a tough position when \"approving\" plugins."

