https://www.acquia.com/blog/drupal-for-government
https://www.drupal.org/industries/government
https://www.zyxware.com/article/6229/top-7-reasons-why-drupa...
https://www.drupal.org/openplus
https://www.applytosupply.digitalmarketplace.service.gov.uk/...
Now most may be a stretch, it's a hard metric to calculate without going around and counting every gov site. But for English speaking countries, it is very popular enough so that I'd say most gov/state/department websites are Drupal.
That and I am a Drupal consultant. So I may be biased.
Tell us more. (A lot more. "Extraordinary claims require extraordinary proof".)
Modules/themes on drupal.org which show "Stable releases for this project are covered by the security advisory policy" are written by trusted users. There is no other protection from rogue code because they are inherently able to access the database. It utterly doesn't matter what extension points the code supports and how because of that. In very broad strokes, if you are using any CMS which a) accesses a database b) allows installing additional code and it runs that in the same process as the CMS code accessing the database -- then you are vulnerable to rogue code. Like, a headless CMS where the frontend only talks to it via an API is protected from rogue code in the frontend part but that's about it.
This means the Drupal ecosystem is vulnerable to a supply chain attack, yes but ... um ... that doesn't make Drupal design insecure, does it?
And once again, what does rogue code has to do with Drupal? Nothing. The same would happen with almost any system. Name any CMS which is actually used in the wild and doesn't get compromised if you install rogue code right into the codebase.
I mean if you built a site from scratch in Spring or Next.js and you start using third-party libraries or UI frameworks, all those third-party bits have full access to everything too.