I haven't found it in the code yet, but the landing page's protocol diagram with optional "/auth/verify" might have potential to be abused as a decryption oracle. It depends how they check the nonce.
I didn't know gpgauth existed, but this is what they appear to be using (the site has a broken cert): https://gpgauth.org/