Methinks having the code there, however suspicious that might be, doesn't prove intent. It may very well be an oversight on there part, or the action of a single mischievous programmer. Of course I don't, and probably will never be using ES5, especially after exploits of this caliber.