Having self learned C devs do a big, complex program is an invitation for security vulnerabilities.
Most of the time people find themselves fighting against the language, and struggling to have the program simply not to crash.
If you see that, you start to think how much those guys would have time left to ensure anything like input sanitation, or code hardening in general.