You might want to make a big fat warning on this post and in the READMEs about this point. It was only clear after a bit of thinking, that this really is intended to be something you run locally.
You might even consider adding some strong speed-bumps before anyone can use something other than 127.0.0.1 to serve content.