The sessions module is currently insecure due to its fixed key. This should probably be fixed. (It should more than likely be supplied with both keys so that it uses encryption, as noted in the documentation.)
You should probably also change it to use the new Gorilla repositories.