Are you open to PRs that add linters to the codebase? I was thinking to add golangci-lint with gosec enabled alongside their default battery.
This is to both help clean up the codebase, and to reduce the likelyhood of security issues arising from use of this package