If the security of your platform depends on that platform not become a popular target of hacker attention then sometimes it really is as simple as "I don't need to outrun the bear; I just need to outrun you"
If the security of your platform depends on that platform not become a popular target of hacker attention then sometimes it really is as simple as "I don't need to outrun the bear; I just need to outrun you"
Just because a platform is small doesn't mean somebody isn't going to try and bust it and when they do the small project may not have the resources to push out a robust fix quickly.
Witness Dropbox vs. TarSnap. Dropbox has had multiple serious security vulnerabilities published. TarSnap is by the FreeBSD security officer. Yet Dropbox is the one with the million+ users and $B+ market cap, because grandma cares a lot more about being able to figure out how to use the product than about what happens when the product gets hacked.
It's more likely your app will become a target when it's popular among users.
This is possible because it can be computer-automated.
If you're in a situation where a teenager has to get bored and specifically tinker with your niche software then you may already be a large step ahead.
I mean, right? If we take it as true (as many are claiming here) that all web frameworks have security vulnerabilities and Rails is just being picked on because of its popularity, then you essentially need to make the decision between having 24/7 ability to quickly upgrade all of your running Rails installations, or using something not as popular.