Yes the hosters have to keep that in mind. It's warned 2 threads here about this situation could be a security risk.
It's up to hosters to keep their 3rd party tools and configuration safe enough. The csf=no is a manual configuration setting, not a DA automated setting. So one should always be...