Line 91 of 3.x-dev 7520320 should attempt to validate the referrer before generating the request. Side note: there are a ton of static \Drupal calls in this module that should be injecting services.