The idea of the plugin is that it reduces the steps required to hide your key from version control—one line to include a plugin, and it does the rest. Yes, there are several attack vectors for retrieving an API key, but the point is to reduce those vectors / make them more difficult to do.