It seems that the default status page script uses an iframe without sandbox attributes, so it can cause some security audit issues.
Can this be added to the script by default without developers having to extract it out?
Thank you.