|
I don't think it would be a risk, as they would be including your file (most likely) through HTTP, so you server would evaluate whatever the PHP was, and send the result (e.g. the HTML) and their page would then just be including the HTML. I'm pretty sure that's how it would go... :o
|