I meant sanitary in a general sense. Maybe a better word would be “unexpected.” You want to minimize the possibility of receiving unexpected input. Though not perfect, the maxlength attribute is one way of getting there.
For example, a password value of a million characters, to me, would be unsanitary, or unexpected. Of course it’s possible somebody might want to use that as their password, but more likely it’s an attempt at a buffer overflow. I’m not saying there is a specific number where it changes from sanitary to unsanitary, but choosing some reasonable value to limit the length at would be a good idea. Even outside of security, from a purely utilitarian perspective, it would make sense to have some limit on the length of any data you’re storing/processing.
Re: security, yes, there should be a reasonable minimum length as well.