Have you ever written a flask app yourself? It provides identical protections against xss etc. that you mentioned, as well as an auth plugin and tutorials on doing auth right...
I think it's unfair to spread a negative opinion of Flask because you had to work on an app that used it badly.