It really depends on what your threat model is.
For most people, the threat model is primarily malware attacks, against which even a homebrew TPM will protect. Ideally you'd want something that literally can't be reprogrammed from the host, but even then, since it's a custom-made device an attacker would need to manually reverse-engineer it to attack it so you'd still be safe against anything but a targeted attack.
Of course, this assumes you even care about using the TPM in the first place. If you just want to satisfy Windows' requirement then security is not a concern at all.