IMHO we should promote using TeX, not discourage it. If we say, if you
would like to use all power of PDF, do not do it in TL because you
currently need AR for rendering the PDF file. AR is not free according
to FSF, thus packages generating such a code cannot be in TL because
no one dared to make a free implementation of a PDF viewer capable to
conform to the whole standard. You should rather use M\$ Word because
you are not required to install anything, you just drag it by mouse
and it will hopefully work. I do not consider it good precedence.

Saying that AR is vulnerable is not a good argument either. The same
holds for ghostscript. If it is not run with -dSAFER (and you never
know how it is configured on a user's machine), malicious PS can
damage a computer. Such a code can be generated by TeX + dvips. Will
you consider removal of dvips because it can generate malicious PS
files?

If pdftex or xetex is available as a web service and users are allowed
to insert arbitrary TeX code, this small file can reveal an
information useful for attackers unless the default TL configuration
is modified:

\documentclass{article}
\begin{document}\tt\obeylines
\input /etc/passwd
\end{document}

