In https://docs.securedrop.org/en/stable/source/how_to_submit.html we currently recommend changing the security slider setting if the JS warning is shown after a user visits a SecureDrop.
We should instead instruct sources to change it before visiting the onion address, so that any malicious JS on a compromised instance doesn't get a chance to run. We can still keep a reminder to do so if the warning is shown.