The problem with this for me is that it doesn't run in an iframe, say, but directly in the JavaScript context of the parent page. This means a malicious site can use AJAX to send all the data it can get back to the server. A privacy concern if you ask me.