One of the reasons PHP gained so much traction was because it is very easy to deploy and run, no dependency hell. WASM is self-contained and has the same property.
I think WASM may have bigger problems with external vulnerability assessment team identifying those modules by version that got broken.
It is often the job of vulnerability assessment team to get down to the root of the misbehaving components, WASM or not.