Interestingly enough someone found a [security issue](http://www.antihackingonline.com/potential-risk-of-cve/cve-2021-23654-this-affects-all-versions-of-package-html-to-csv-the-flaw-let-threat-actor-can-embed-or-generate-a-malicious-link-or-execute-commands-via-csv-files-26-11-2021/) in this code but failed to post a pull-request or even report it: https://security.snyk.io/vuln/SNYK-PYTHON-HTMLTOCSV-1582784