Receiving zaps on your umbrel is a bad idea.
You expose your entire node to DoS attacks.
To initiate a zap, all it takes is one request. The node has to then create an invoice and monitor it until it's paid.
Its trivial to create a script that creates endless "zap requests" for one receiver. With every new request, there's one more invoice to monitor. Sooner or later, the node is 100% busy checking pending zaps and cannot do anything else anymore.
This is different than normal LNURL, because there, after the invoice is created, its not monitored.