I access radicale via an nginx proxy with proper HTTPS (LetsEncrypt) and an HTPASSWD over that, so the setup is secure. However radicale default setup is not secure, I agree.
Radicale is a great FOSS solution for syncing via the CardDAV and CalDAV protocols. I simply prefer using end-to-end encryption for extra protection where possible, which is why I think EteSync is a good alternative. E2EE means that even if the server is compromised, my contacts, calendars, and tasks won't be.