"Add NoScript to it and you're golden" but of then course the site will not work as it's a javascript behemoth. No loss really though ...

The thing that really does piss me off though is the huge upsurge in static page sites that depend entirely on scripting. Typical is the National Cyber Security Centre site that (the last time I looked) won't even render a landing page unless scripting is enabled. Given their notional function they should know better. Security 101 "don't download and execute untrusted code".

