Quick question - are you concerned about trademarks (Amazon and such) being included as the phishing templates? Reason I ask is that I'm working on a hosted project [1] similar to this and have considered including default templates. I've held off for this exact reason.
Edit - another question, your screenshot in the intro page shows an email (in the Gmail client) coming from "support@github.com". Github has spf records setup so I would be interested to know how you manage to spoof the actual email address itself without getting flagged as spam.