There are obviously some risks here, as the door is opened briefly twice, but there are a number of steps taken to minimize this risk.
The biggest realized risk seems to have been Germanwings Flight 9525. A suicidal co-pilot waited until the Captain left the cockpit. Then he locked the door and flew the plane into the side of a mountain.
An attack can be designed against any vulnerability. Whether that attack becomes practically executable remains to be seen.
Protocols to ensure two crew members in the cockpit at all times are now being considered.
There was an exceptionally good essay on implications of this incident, with computer/systems security implications, though I cannot locate it. James Fallows' Atlantic piece was good, though not quite what I was looking for.
http://www.theatlantic.com/international/archive/2015/03/ger...
As we've seen, a plane can be devastating when used as a weapon, so I think it is sensible to deny terrorists to the cockpit at the expense of the passengers. Theoretically, there are few situations where passengers can be forcibly restrained, since they should outnumber any people trying to seize the plane by quite a bit, passengers could (and have[2]) attempted to neutralize the threat themselves (as they understand the possible consequences of waiting out the situation in this era where the goal is not money, but chaos).
Even if we did away with security entirely and let people carry guns on board, there would be literally zero risk of a hijacked plane in the US thanks to the locked doors. (There might be other reasons not to do that, but hijacking fears are not one of them).
And even then, it's arguable that this would still be impossible. 9/11 happened because hijacking protocol never took into account the possibility that the hijackers would use the plane itself as a weapon. The people on the final hijacked plane on 9/11 did know this, because they received calls about the WTC, so they fought back and forced the plane to crash, thwarting the hijackers' plans.