OSCommerce, a potential security risk?

Webman asked: So I hear that programmers can code and add add-ons to OSCommerce. But can’t this be a really big security risk? Like, what if someone goes in there and deletes the entire OSCommerce system? Or adds a virus to it?