> if not validated
I thought script tags were an official part of SVG? Meaning that a valid SVG can contain embedded JS.
he must have meant to 'sanitize' or 'filter'