Allowing unauthenticated access is the default configuration, but I think you have to go out of your way to make it accessible from external systems, let alone by anyone on the open internet...
My thought process is deploying this on digital ocean would make it insecure by default.
https://docs.mongodb.com/manual/reference/configuration-opti...