It a decent script. Its just like any other open source script with regards to exploits. Just make sure you are on top of the updates. I saw the email didnt jump right on it and paid for it. Two of my sites got hit and google promptly slapped the 'virus' tag on them.

I updated and google had me back in the clear within 6 hours.