Conntrack/NAT helpers can sometimes be useful, but a lot of the time they were useless or, as the latest security research shows, outright dangerous: https://www.armis.com/resources/iot-security-blog/nat-slipstreaming-v2-0-new-attack-variant-can-expose-all-internal-network-devices-to-the-internet/
I believe we should change that syntax to disable them all by default and allow enabling them.
This will break configs for existing users who rely on them though. It should be relatively simple to make a migration script that creates a config with all modules enabled on updating from 1.2.x.