I think there are security issues, as it "works" by copying the HTML of the page and overlaying a canvas on top. So, for e.g., if you post a HN page, I could copy the URL for upvoting, trick you into clicking it and get an upvote automatically. The auth token in the upvote URL is supposed to prevent CSRF attacks, so it's dangerous to give it away!
It's also a problem with websites that store temporary auth tokens on the webpage, though I don't know any.