If you would make custom tags and allow users to load a web page within a post you might as well just turn on HTML in posting for everyone. If someone wanted to execute some bad code an they were not allowed to do it as HTML is off but you are able to pull in a web page using an IFRAME tag then they would do it that way.
Years ago this was used to execute a javascript code in a community and used to grab the Host's user names and passcodes, it worked very well and caused big problems in that community as the grabbed data was sent off to a perl program running in a different location on the internet.