And, and why Open Source shouldn’t be used where security is required.
Oh. everyone knows that proprietary software is 100% bullet proof. /sarcasm
Most people would take the opposite view. An open source framework like Struts is supposed to be written by highly experienced programmers, and thoroughly tested in thousands of applications. It handles the nuts and bolts so each application doesn’t have to re-create them individually. The code your mixed lot of programmers write is highly likely to have many more flaws than well-vetted open-source software.
The downside, of course, is that if open-source does turn out to have a serious flaw, hackers will try every web site on the web to see if it is vulnerable. They will get many hits.