How do I know it's secure against recent security breaches? Apparently the code base has diverged a lot from current Firefox and Gecko, so they can't just apply patches from there. Do they fuzz it, do static analysis, etc.? I guess the main security feature is that so few people use it that there are very few attacks on it.