Most major browsers have fixed this loophole now, as I've tested with my own implementation of this hack here. I think the README should be updated to reflect this.
Your demo no longer seems to be working.