Add a way to force google safesearch through the web interface

Just take it (you modified /etc/hosts) one step further and follow the instructions here.

By using /etc/dnsmasq.d/05-restrict.conf, you ensure your configuration "survives" a pihole update.

If you decide to implement the above referred configuration, you should remove your custom entries from the hosts file.