#1299 and #1300 are fairly big showstopper bugs which were corrected in the v0.4.3 release.
I have yanked all prior releases, though we should probably also file a RUSTSEC advisory and/or CVE.
It's labeled as an experimental crate which doesn't currently seem to have a large number of users, however the current users seem to be using v0.3.x. Hopefully yanking encourages them to upgrade, or if it's a problem we can potentially backport a v0.3.2 release.