Common sentiment is that the miniupnpc codebase likely contains further vulnerabilities (context: #6789).
I’d prefer to get rid of the dependency completely, but a compromise for now is to at least disable it by default, to prevent UPnP vulnerabilities being a structural danger to the network.
Also get rid of the confusing --[enable|disable]-upnp-default
autoconf and define magic.
Edit: needs backport to 0.11 and 0.10