To me, Docker doesn't seem like a good choice of technology for a honeypot, as any kernel-level exploits could lead to potentially lead to complete system compromise or worse.
If they manage to find an exploit in the Kernel then we have something far more valuable on our hands than the run of the mill WordPress malware. Remember, anything inside the honeypot is being aggressively monitored, so we'll know where it came from and what it did.