"Don't rely on a single cipher" is an anti-goal, and a reason your hobby project won't be taken seriously. You'd be better off striking it from the list.
"Zero dependencies" is also not especially reassuring, as it implies you're using your own cipher implementations (or reference implementations).
If unanticipated issues are discovered, end users may not receive the updates in a timely fashion if, for example, the repo owner is the only committer and they're on vacation when the next Heartbleed 0day hits.
I am confident and trust the OpenSSL and LibreSSL projects each have multiple folks capable of merging and releasing critical updates.
Amazing as he is, Filippo is a single person who presumably has human needs. If he's a Terminator, though, swell, do let me know.
Ah. I was thinking the critique was about combining different crypto methods in serial; I've heard people say this is a bad idea but have never understood why.
"Zero dependencies" is also not especially reassuring, as it implies you're using your own cipher implementations (or reference implementations).