It's like any other system designed to be used by people that are not technically savvy. Lots of things have default values that are not sane. That's why the script kiddies hit every server they can with known defaults and vulns. Otherwise, it's like any other publicly facing internet server in that it takes maintenance with patches and updates and being informed on what you're running and changes being made.
So because the majority of users are not savvy, it's become a cesspool. Then you read about it on a tech forum like HN and it is derided as an inferior product rather than allowing improper use by the user/operator.