java plugin was a reputable good security sandbox. Features were added and some subtile security problems were found. Oracle repeatedly failed at fixing these problems because it wanted to avoid breaking old applications. The consequences of this bad management is that the reputation of java plugins is bad and they are prohibited in many enterprises. The problem is only a management problem, there were not technical reasons. The idea of having java application in a safe sandbox is perfectly viable except oracle.