None of the four bullet points actually address real issues. The security problem isn't that Google is bad at security (they're among the best really). The problem is that Javascript code is generally written with the expectation that it will run in a web browser's highly locked down security context. Performance is really the same issue: web apps are authored wastefully. For use cases where you visit a web page for a few minutes then leave that's fine, but when you then let that code run for hours with no sandbox you will inevitably hit perf issues.
Write native apps. If you can't afford that, just make a web page.