As it connects many devices in my network, a vulnerability in Tailscale will have a significant impact (they had recently a nearly 10 CVE). That’s not the case with the standard client server approach (clients can run user space Wireguard).
Even though I don’t open ports with Tailscale (more precisely, I outsource them to Tailscale), I still can’t sleep well at night!