Right, but the point of this article is that it no longer needs the admin password. If you're running in a non-admin account (like I am), it'll still need the password, and thus user interaction, so it'll be trivial to stop.
True. Somewhere I thought I read that the installer ran without user interaction in this variant, but thinking about it, that doesn't make much sense.
Though, if you're concerned about having to give an admin password (as evidently some people are), running in a non-admin account would solve that. (Also, if you have write privileges to /Applications, it's possible to write a script overwriting the contents of a trusted executable with malicious code, but that isn't how this works so it's slightly irrelevant.)