Are you not aware of the zero day exploit recently uncovered, which Oracle has not made any show of trying to fix? Unless there's been some very recent development on the issue that I'm unaware of, I'm keeping the thing far away from my system.
Doesn't matter if it's not run by Oracle or not, they're still using the software. It's not so much "shoot the messenger" as it is "don't let the messenger near the border".