@ampforwp, while it’s understandable that more features lead to more difficulties in keeping the plugin secure, some vulnerabilities found by sybrew are anything but minor.
To quote the link provided by @adpawl:
I’ve found various exploitable points in a twenty-minute scan, these exploits notoriously include file injections, backdoor file downloading (including wp-config.php), DDoS vulnerability, database upgrading, options-and post-metadata overwriting, bandwidth exploitation (full WP media-library downloads), and unfiltered WordPress post injections.
All these exploits do not require any administrative privileges.
Aside from this, they embed the Redux framework, but they’re not keeping it fully up-to-date. I didn’t bother scanning this thorougly, but you can also adjust a few site options in there.
This is very serious, and I believe that you, as a developer, should provide a honest and deep explanation and issue a warning to all users, asking them to update the plugin ASAP and cease to use unsecured versions.
It’s beyond my comprehension why, under such circumstances, did you write:
No serious issues, to be honest