Earlier quoted context omitted.
How are they isolated if you can inject JS that downloads resources from anywhere else? I mean, just to start: - You have no CSP header that I can see. - You do expose the server version in the headers, though. - The site is available at a non-SSL-secured domain. - There's no X-Frame-Options, X-Permitted-Cross-Domain-Policies, etc.
My point is, the service simply hosts HTML, ostensibly this is the same as any consumer web host. So whatever attack vector you can think of exists on Dreamhost or Godaddy pages, for instance.
I have worked for companies that offered commercial web host services and it is a massive security undertaking. I'm still not 100% convinced it's possible to offer a profitable, truly secure web host without compromising on feature set.