From building some pages recently with craigor its quite interesting how easy some of this stuff is, even posting your own content to a form submit page and then looking at the $_REQUEST value that it returns can yield some scary information.
IMO if your making something public, even in alpha, it should be locked down.