Please don't.
If you were a doctor with a disease carrying patient, and that patient wanted to leave the hospital, possibly contaminating other people, it isn't enough that you make them aware of the potential risks, you must do what you can to prevent the spread of disease, not hold the door open so they can leave.
The fact that you intend to "figure it out myself" isn't going to show us how clever you are, but how foolish you are, because clearly you don't understand all of the potential risks (so how can you possibly explain them to your client?).
As an example, of one thing you probably haven't thought of; I'll wager that this client has also chosen the cheapest webhost possible, which means there are possibly 1000's of other websites using the same server.. When your client's site gets hacked, it exposes *all* of the other sites to the hacker. One of those sites may belong to a lawyer that'll have no qualms of taking a class action against *you* for the damages caused if it is known that you deliberately circumvented the inbuilt security measures. If they only get a few $hundred each you'll still be screwed for life.. and for what? To keep an idiot for a customer? Not worth it if you ask me. You're better of letting them find some other sucker to do this dirty work, and you can come back later and charge a fortune for cleaning up the mess.
If you're smart.
Cheers
Rod




