It still needs a server to relay the webrtc peer discovery stuff, at least by looking at server.js ?
Ended up deciding to spend the week configuring jitsi, but all it took was 1 hour to install and configure the server and I was done
The development of the frontend is a bit messy, but you'll manage
Or can you?
The NAT hole punching is done by the STUN servers listed in script.js. They appear to be public third-party STUN servers, so that could be a vector for a malicious actor. There are also third-party TURN servers listed, which will relay media in the case that NAT traversal fails. That should be ok too, but could also be another attack vector.