To reliably run this DNS server I would have to have another host on the network that uses a separate DNS route that checks every entry on pi-hole against the secondary to confirm something fishy is not going on.
Also, not sure how I feel about having this device as my primary DNS server for my entire internal network. What if the project gets compromised and injects a number of malicious DNS entries, now my entire network is toast?