"This is their response:I am sorry to be the bearer of bad news, but we have been conducting a code review and the mrbs block is unsupportable in its current state and will need to be substantially rewritten, in fact there is a page about it here http://securityreason.com/securityalert/3492 The way the code uses $_POST and $_GET in emulating register_globals leaves it vulnerable to cross-site script" . . . .