How hard it is to add config option to do that? Even if it will be false by default, who knows and who wants can easily switch (enable) it. I understand of performance, but i think that security is on first place.
+1
Could not find such option in ExtJS 2.2, missing it greatly.