If you're sourcing the script into a context that can have side effects, it's not safer any which way. That's why I keep returning to the HTTP/IPFS boundaries. The risk profile when crossing between them isn't the same as when encapsulating in one (even if embedded).
♥ 1