My chosen threat model does not allow for significantly less security in exchange for extensions.
Also, they may very well take PRs for extension support (haven't looked through their Issues/roadmap), but, I'm sure it's not on the top of a security-first project's to-do list.