Current implementation of securing webhooks could be much better by utilizing an hmac-based token as opposed to just including the plaintext secret in the url query string.
You won't be notified about changes to this idea.