We can say the same about most of open source.

It's the WordPress plugin ecosystem that's more often the security nightmare though.