How is it:
based on 0.3.23, tracking changes as they come in
and closed source?
I won't be touching this until someone ILDASMs it and proves it's safe

(Even in VM, hwo do you know it doesn't only work x days into the future on the xth second, or something silly, or if a certain transaction is in a block it picks up!)
See my earlier points about only testing with trivial amounts if at all.
I would also like to point out that it would quite monumentally stupid for us to have AllBitcoin do anything fishy at all. Any breach of trust would render all of our hard work so far useless.
I support all investigative efforts - monitor the traffic, disassemble the code, dump the memory. Look for unencrypted private keys or password - it should be highly unlikely to capture one in a memory dump and absolutely impossible over the network.