Sure, you take a hit running it under CGI, just like you do with PHP under CGI. Most ISPs are offering PHP through either CGI or FastCGI (mod_php has all the same security issues mod_perl does). Perl has the same options, and embedding Perl works with both.