Hello,
is and young component and it is modified significantly from release to
release.
We will add more and more preg expressions for php am sql injections with
every new release.
Sitemap generation will not be considered as Flood because it is not
generated using HTTP protocol.
PHP injection will not make any difficulties to your CB users until they try
to inject

I am not sure about 1.5 at the moment due to Joomla license policy. SO I can not tell you for sure but most possibly we will transfer all our components in September.