As a cautionary example, see https://stackoverflow.com/questions/5021456/how-does-mongodb.... The question was why MongoDB was by default able to avoid the equivalent of SQL injection attacks. My answer took what was in their FAQ at the time, and expanded upon it based on advice from D.J. Bernstein - who is famous for his ability to write secure by default code.
Then it was discovered that PHP volunteered to create security holes in MongoDB. Then it was discovered that multiple other languages and libraries likewise volunteered to do so. Had they followed the good advice that I was quoting, the problem wouldn't have happened. Despite the other faults of MongoDB itself, in this case it was truly innocent. The security problem wasn't in it, but in the libraries that were written around it. It made it easy to write secure code and they didn't.
But the result? From the point of view of a naive programmer, not long after my answer appeared it was revealed as misleading for PHP programmers. A few years later, it was actively misleading for other languages. And while the advice remained technically correct - which is why I left it - it has been criticized on reasonable grounds by several other people since.