Perhaps the worst offense was the insecure-by-default config I mentioned in the other comment. I was unknowingly running it on a public port on a dev machine without auth for months before I realized (the network I was on didn't happen to filter inbound connections on ports >1024).
I used Node-RED pretty extensively for controlling experiments (see e.g. https://github.com/avian2/sigfox-toolbox)