hrjet > typically other factors are of greater concern, like cpu usage for decoding, filesize of JS based decoder, total savings required to justify using a js decoder
Those are characteristics of the implementation just like the security issue. I don't think that would hinder adoption. I wonder whether the spec / algorithm itself doesn't have big appeal (judging by what is visible in the public).
The time required for decoding FLIF, for example, is a hurdle since much of the algorithm is sequential. But again, if there is good momentum, a future version of the spec could be made less sequential, for example, by supporting tiles natively.