I think it would be a very good idea for moot to bite the bullet and pay for a moderately thorough security audit of 4chan's code.
This one-time investment would hopefully resolve most of the major/obvious security issues. Then the code could be open-sourced with moderate confidence that a million 0days would not be exploited instantly -- and the community can catch the obscure holes.