I'm more concerned with the fact that they're telling you all that it's not secure but a loop hole. It's not PCI compliance but rather avoidance.
As a business owner/manager and credit card merchant your primary goal should be keeping customer data secure.
Stripe has multiple methods for integration. Why would anyone just assume it's using stripe.js?
I really don't see the big deal with documenting it to make everyone happy, it seems simple enough, but I also don't get the witch hunt here.
If you didn't know before, you know now.