Sorry, a world where every tool is riddled with security holes by default and every developer needs to learn them inside and out to close them all through configuration is a ridiculous burden.
Is it really that difficult to require someone to set a secure password before a product is usable?