Since this is about my original comments, I might as well weigh in on it.
First, I agree that if this is truly a fully open source software, without obfuscation of any source or associated libraries that may be linked in, then the chance of malware being introduced is very low.
Now, to the main topic at hand. I too get spam from email addresses I've never had, but that is not the point. I've got spam that was from an old email address I had, which is rather amusing, but still not the point. The design pattern I use for my disposable email address is not one that is easily reproduced by anonymous email engine that builds email address from existing information. This is the first time I've actually received spam based on one of them.
The email in question is one that I created about 5 minutes before using it on this site, so it could not have been harvested prior. I had not used in it any place except registration on this site, which I would suspect is not persistent so that a spambot can walk the site and gather it. If it is, then I would say that not everything is being done on the site to safeguard the customers privacy. In a private message to Andy (of which there were several which Andy did not mention in his above posts), I said the leakage of the email address could be either intentional on his part, which he denies, or a weakness in one of his systems that is being exploited. If it is a systems issue, as he seems to be a talented developer, he should be able to find and close this vulnerability. If its a GoDaddy.com issue, who hosts this site, then I would expect them to have tight control of these types of issues, since they are a large and fairly respected "hoster", and would respond adequately if notified it was indeed their issue. And they do have some anti-spam policies in place as a part of the Terms Of Service.
So, to recap, a new email address is created for use on this site, and was not used external to this site. It is not persisted by myself anywhere (to include this forum) that is knowingly externally exposed to harvesting. The only way it could have gotten to spammers so quickly is that it was intentionally released, which again Andy denies, or that an external systems is somehow harvesting internal information to this site. Either of these are bad avenues. And if an external systems exploited a hole in the system and was able to get the information so quickly into a spammers database and be released into an actual spam email, perhaps indicates it knows that this site is exploitable. So I stand by my original position that my email address was 'leaked' from this site, and from this site alone; whether it was intentional or a hole in one of the systems that allows exploit, I can't say definitively. If Andy says it wasn't intentional, then I will tend to believe him, based on what I see of his work and his interaction with the using community. But that doesn't fix the problem. Speaking derogatively about me, and rather childish at that, is not the best way to handle this.
Thats my logical view of the situation......