We’re currently running ‘Summer of Pwnage’. One of the participants noticed that with this plugin enabled any user with role Contributor or higher can run arbitrary PHP, which is normally only possible for Administrators. It may be good if the plugin allows you to control who is allowed to run PHP.
Eg, have a setting in the plugin and when parsing the shortcode check who is the author its roles.