Just got hit by #24 because I expected no potentially unsafe options to be enabled by default.
Furthermore the https://github.com/paolochiodi/htmlcompressor#usage documentation has different "basic and safe default options" than middleman-minify-html