This is a difficult variable to control for - especially as it is an open source solution. My hunch would be that many scam sites will use some straight out-of-the-box setups instead of more sophisticated tools like Medusa. But we would definitely address it should this become a problem in the future