Document PMASA-2013-1
It turns out that release 3.5.8 (recently updated in ports) was the cure to an XSS vulnerability.
Feature safe: yes