You could write good-quality secure code in Perl, but the level of dynamism in the implementation and the fact that there’s only the one main implementation means there’s not much hope of quality static analysis.