In contrast, I'd say a pure-C web page would be way easier to open to attacks than a PHP one.
String copy issues (termination), buffer/array overflows, machine-code (R)CE vulnerabilities,... an endless list of stuff which the PHP runtime actually protects a novice of.