Updates are critical to a safe site built on Wordpress. If updates are maintained, Wordpress is a terrific solution. I would always add Wordfence and Spam Blocker.
If a Wordpress blog is left unmaintained, it can and usually will be hacked and defaced, if not worse.