i think if youre using iframes for other people's sites you definitely should be disabling JS execution with the "sandbox" attribute:
One, I think that's really cool. I didn't know you could do that. Two, that kinda takes the way the whole point why certain things are iframes. For example,
Gifypet needs JavaScript to run. Your pet wouldn't work if you disabled JavaScript.
That's why I don't embed anything from other sites on my site.
Also speaking of Gifypet, I do find it interesting that you say this even though you have one on Libre.Town's home page. Though, I assume that's because Melon is seen as a trusted individual/friend. (p.s. Your pet is really cute)
I kind of thought something similar when it comes to links specifically. There is still a possibility that someone can change their website that you've linked to something malicious or uh.. of bad taste.. but mutual trust happens to be a very important part of a strong and healthy community.
Yeah, this is basically the reasons I'll link to people and use their iframes. A community built on distrust isn't a community; plus, I typically don't assume malicious intention from people without reason. I'd personally like to believe that most people don't create shareables with ill intent, though I do understand the worry and reality.
This is kinda why with my own iframe-ables I've created, JavaScript isn't necessary for them to look good and work. Yeah, certain customization might not be there but it'll still work. I personally roam the web with JavaScript enabled, but I know there's people that don't so I try to accommodate that when I can.
This web garden looks nice and dandy, but maybe a static image of the sites and a "report" button would be enough against that security nightmare of Frames or Iframes.
Travelling across the internet without some kind of script blocker is a whole nightmare in itself!
I dunno, I feel like the whole point of web gardens it to be interactable; that's what makes them unique to other shareable / adoptable things like
Teeny Towers. I could see a separate option where it's plain HTML and CSS code blocks you share instead though.