You are not using HTTPS - encrypted communication with the user. HTTP works fine for test purposes, but in a production environment, you should use HTTPS. [ Read more about simpleSAMLphp maintenance ]
The configuration uses the default secret salt - make sure you modify the default 'secretsalt' option in the simpleSAML configuration in production environments. [Read more about simpleSAMLphp configuration ]