The risk of that happening is equal to that of any site one uses on the internet.
Though I would argue that the browser one uses is the malware. Javascript can access that malware and make it act. Visiting any google site allows them access to the malware platform known as the "web browser".
The onus of security has always been on the individual.
I agree, which is why the domain text shouldn't be removed for Pic8. If it's removed people won't see that it's a Pic8 link and won't consider the possibility of exploits.
(post is archived)