Web::API 2.8 and earlier for Perl uses the rand() function as the default source of entropy, which is not cryptographically secure, for cryptographic functions. Specifically Web::API uses the Data::Random library which specifically states that it is "Useful mostly for test programs". Data::Random uses the rand() function.
multiple wrapper keys, get_params auth_type, better XML::Simple options (please someone write proper XML encode/decode support. maybe even choosable XML parser with great defaults)