And updating things that generate content dynamically each time a security vulnerability is discovered (which for most popular frameworks means often) is such a PITA.

An amusing but tangential implication of this is that less popular frameworks are either 1) more secure or 2) equally insecure but less explored. Hope for 1 but assume 2, because security is hard.

