- It was a huge gaping security hole, and now HTML Purify will remove the src attribute of all non-allowed sources anyway.