I run a demo site for Roundcube @
Mail4us.net Webmail :: Welcome to Mail4us.net Webmail. People are able to register their own account anonymously.
I prevented Roundcube from spammers very successfully:
#1- Block smtp port (25) for connections outside your LAN. Only Roundcube is able to send mails.
#2- 'dnsbl' plugin to lock out connections to Roundcube from blacklisted IPs.
#3- 'limit_recipients' plugin to restrict sending out bulk mails.
#4- 'blockspamsending' plugin to restrict sending out mails with same content within one session.
#5- Finally I configured a delay of 90 seconds to send messages ( $rcmail_config['sendmail_delay'] = 90; ).