> The core WordPress is one of the most secure software in the world: there are thousands of people trying all the time to find exploits and the codebase is public. Go take a look at what CMS whitehouse.gov (one of the highest-profile hacking targets out there) is using.
While I believe the core is reasonably secure, lots of plugins and webhosts aren't. Simply making the website code read-only would take care of a lot of issues, but then your auto-update won't work.