I disagree. There is no danger in that script. Granted I didn't do much of a test, but at least I check that it is really a directory. How much damage can a script do trying to change directory and glob for known extensions? Not much. In fact the only "risk" I can see would be some one looking to see if given directories exist on your server. Not that big a deal. Nor would it take much to add a regex after the -d line to make sure the user supplied directory is sanctioned.