In a situation like this it's safer to say that your profile is safe only if that specific identity is on a white list of known safe identities. Thus things like test will by default, Show as unsafe which is better because it hides information about who is unsafe. If designed right, random form data will simply return unsafe silently. Maybe you could try testing for that.