I did a spontaneous security review of the extension for Miraheze (https://issue-tracker.miraheze.org/T12870), and here's what I found:
- ~9 XSSes (I lost track)
- The ability to import pages while blocked
- CSRF when import pages
I gave up fully documenting the security vulnerabilities once I stumbled upon the CSRF, so I'll just submit a solitary patch instead.