The caution is that if you upgrade to a newer BaseX version, presumably in a new directory, your password and port will get reset to defaults, opening up your site for remote access! The default from a security perspective should obviously be that BaseX listens only on "localhost" and no other network interface, or doesn't listen to any port at all, without a configuration, but I don't think it is shipped that way.
True; if you want to adopt users and passwords from another BaseX installation, you’ll also have to copy the .basexperm file.
Christian