I think that N++ is a one-programmer project.
Don Ho seems like a really cool guy.
I hope he is able to get the patch Incorporated, because it sounds like the security team provided one.
Thanks Don, for your work; and thanks Jaroslav, for the security discovery.