how bad is it to set allow_url_fopen=on?

I'm digging the Reports plugin, but with allow_url_fopen set to off in php.ini, it can't generate QR codes.

If I change it to on, am I making my site terribly vulnerable?

ken.