Neither is inherently less secure than javascript running in a web browser.
> and poorly integrated with the rest of the stack.
Yeah, but, so? Maybe I'm too old and curmudgeonly but I preferred it when applications acted like applications and websites acted like websites. Now I have to deal with websites that are half application, without the responsiveness of either and built on a pile of franken-code.