Why don't we all screw our heads on and use a little common sense. We don't allow the files to be downloaded but allow the txt file with the uninstall instructions to be downloaded so that any security issues can be acted upon and dealt with by the people who have the script installed.
It's easy to say that the instructions are in the first post but this is not always the case they are usually in the txt doc.
What your basically doing is sending an email out alerting of an exploit, security issue but not giving the info to the person to uninstall the script and files.
Just a suggestion, I haven't made one of those for a while.