How about CORS version instead of JSONP?
http://www.stockhouse.com/companies/bullboard/t.y/yellow-med...
....should I be seeing anything in the "Example json output" box?
There's a reason browser's have same-origin protections: to stop spammy behavior and protect against malintent by original or injected scripts.
This service will be fine for a bit, but once it's used for the above purposes, it'll end up in blocklists.