Mailpile: crowdfunding a secure, private email client/cloud service

My guess is security falls apart with the “plugin architecture”. Is there an easier way to break a secure system than to let a community of amateur coders start writing plugins?. I can see the avalanche of sql injection attacks in my head already.