I don’t think WoT is enough on its own but the friend request thing doesn’t scale alone either.
The attacker has an unlimited supply of identities to spam with “friend requests” (that was/is a problem with Matrix room invites, and that’s only federated system with DNS acting as a prefilter).
