I saw in your blog post you are getting close to version 1.0, congratulations.
I was just wondering if there were any plans to look at security of the admin plugin before the release? In particular CSRF and XSS would seem to be risks once you have a privileged user performing actions via a web interface.