Thank you all for your comments. If I recall correctly, the option to disable DDE was mainly added to allow users who ran multiple copies of mIRC to disable DDE in all but one copy of mIRC, as otherwise their DDE requests would interfere with each other. It was not added for security reasons.
Disabling DDE or SendMessage would be a minor barrier but if a malicious application is running on your computer and it is aware of mIRC, it can already do anything it wants, which includes modifying your mIRC settings and scripts or sending messages to the interface. In any case, I will add this to my to-do list - it should be easy to add it as an option to the Lock dialog "disable commands" list.