Built and live since this morning, so this lands at a good time, and one of your three points found a real bug. The escape hatch: the frame's footer bar already opened rivok.io in a new top-level tab, so that part was covered. But one level down it was not. The sign-in links inside the game itself had no target, so in the frame they would have navigated inside the frame. You would have signed in successfully, into a context the session cookie never leaves. A dead end with no error to show for it, exactly the kind nobody reports.
Fixed: in a frame, every account path now breaks out to the top level, including the sidebar links, which all lead away from the game anyway.
The window.open trap does not hit us, because there is no window.open anywhere in the client, it is all plain anchors with target="_blank", which sidesteps the problem rather than working around it. Your warning is in the code now so nobody refactors into it later.
Storage partitioning I had not thought about, and you are right. A guest in the itch frame gets a different guest id than the same browser on rivok.io. It costs nothing here because guests keep nothing either way, and for the traffic numbers it is arguably the correct behaviour, but it would have looked like a bug in three months. Written down.
On the ranking argument: that is the part I found most convincing, and it is why the embed exists now rather than staying a maybe. Whether it actually earns anything is measurable, so I will let it run and find out.
Twice now you have made this page better without playing the game. Thanks.