Keep in mind that those people do not do it intentionally; it's just the script they are infected with. Once they manage to remove it, there is no reason to deny them. Also, $wildsite represents the full *!*@host (or IP) that is likely to change whenever the user reconnects to his ISP, so keeping it for long duration would have no effect.