We take security seriously at MongoDB. Here is a response on security best practices from the MongoDB CTO & Co-Founder:
http://www.mongodb.com/blog/post/mongodb-security-best-pract...
http://www.mongodb.com/blog/post/mongodb-security-best-pract...
> "The most popular installer for MongoDB (RPM) limits network access to localhost by default."
The first download for Linux at https://www.mongodb.org/downloads is:
> https://fastdl.mongodb.org/linux/mongodb-linux-x86_64-2.6.7....
At the bottom of the page there are alternate links to packages. Here is the description:
> "MongoDB is included in several different package managers. Generally speaking, it is easier to simply install the prebuilt binaries from above."
If the properly packaged versions have secure defaults, maybe you should steer people towards them?