I will admit to not actually looking at how third-party keyboards are implemented (specifically, how are security risks mitigated), but have always stayed away from them on instinct. For me, the potential value just doesn't outweigh risk.
Without “full access,” the API surface is basically nil and the keyboard is just a dumb app. With full access, the keyboard can phone home with everything you’re typing. Kudos to Apple for calling it “Allow Full Access” to make people sufficiently wary of it.