It's a funny coincidence that I was just reading this book (https://toc.cryptobook.us/), Figure 4.5 on book page 102, that talks about this exact issue.
I doubt the author realises that the system must be resistant against a class of attacks (in this case, I believe a chosen plaintext attack). From reading the thread, and comparing it to the example in the book, it seems like the non-uniform patterns in the output highlight a possibility of a CPA.
And of course, the author wants a fully implemented + concrete attack instead of pointing to what's an obvious flaw to the crypto community.