Yes, that's the problem.

No, it won't be fixed. You can expect it to be fixed never.

It isn't displaying "a segment of an FFXIV character's internal account ID", they send the whole ass account id to the client, raw and unencrypted and it isn't "used in an attempt to further correlate information on other characters on the same FFXIV service account", they just use the whole account id that they're being given to look up other characters with the same account id.

This is the devs refusing to acknowledge that this is even their own fault.

Absolute best case scenario, the plugin will just be made private again. But I'm pretty sure the people who would still have access to it are on my data centre, so that's cool.