Fixes T6416. The comment is consistent with intent, but the actual regexp doesn't quite work right. In particular, we incorrectly match #security. as security. (with a period) instead of security (with no period).
Since this stuff is a pain to test and I evidently got it wrong in this case in D8703, make it unit testable.