I think more about the fact libxml and libxslt are large pieces of code and have had CVEs raised against them (and fixed) in the past. They are still actively maintained.
I think the idea is the increased security risk of potentially poorly maintained large body of code with a wide surface area.