Author here - I should maybe have made the disclaimer at the end more prominent - "All the bugs were discovered, verified, and reported. Any issued tickets were canceled and not used."
Good point. But the sandbox attribute is around 90% [1] of browsers. The number of browsers which don't support it and don't run javascript may be too low to make supporting them practical, but YMMV.
If you apply the sandbox attribute to the iframes it should be ok. It allows fine grained control of what the iframe is allowed to do. Scripts, navigation, popups, etc. are forbidden except explicitly allowed.