package: libsaxon-java severity: whishlist By default, saxon allows arbitrary java methods to be executed from an XSLT. Please add a warning that this has to be switched off if untrusted XSLTs are used.