There is, as far as I have seen, which is to sanitize the content that is provided to the maximum extent but to still be within the operational parameters that are expected. It is undesirable to take just *any* content provided and try to feed it to the processor as that content could contain something that would be undesirable for either party. Also, that way the content entered can be provided a response prior to being processed and when handled can support a better user experience. The numbers rarely change or are added so things can be consistently controlled.
Bookmarks