Thank you for your explanation.
Yes, it seems you are using it in the right way. But it would be even better if you can get rid of it. Some exploit can be found on it, so this file should not be reachable on the server to improve the overall security.
Anyway, you’re doing a great job with this plugin !
There is an issue with this pluggin I think. It uses a file located in the wp-admin folder which can leads to serious security concerns.
The author should take a look at it.