The only thing Security::generateToken was providing was a default value for the $action, which created a pattern of using the same $action everywhere, which may not be the best way to go. Since it was essentially a wrapper for WP's built-in nonce functions, it seemed clearer to use those functions directly to be more explicit about how we're handling tokens. [MAILPOET-2030]