Good point about progressive enhancement. We could add that as a best-practice suggestion to 4.5 "Consider the slowest, least capable.."
Note that the "security concerns" are due to exploit code uncovered in polyfills that can't be easily/quickly patched. The point about "generally not written by browser vendors" may be a distraction that can be dropped. Cut to "may not have the infrastructure..."
From #8