Well, it looks like I'm finally going to do that code reorg.
First up, secure the site. The first step of that is to require an SSL connection. Not total security but a first step. After that is better authentication/validation and such. Then audit the code to see where it can be more secure.
Of course, I do need to make the site "prettier". Call that step 1 and a half. :-)