2
Don't know enough about modules to answer your question about how they are constructed, but you have identified a problem.
Unless the module is still developed and supported by it's creator, you may have a hard time patching security holes. The osCommerce mod is AFAIK unsupported. The xphpBBi port of phpBB is unsupported (developer just upped and went). The phpBB mod from bbpixel has limited support. By limited, I mean that there was no patch for the recent Santy worm that hit the version of phpBB used by the mod at the time, even though phpBB released a patch. The mod has been upgraded recently, but I opted for bbpixels IPB board, simply because it has better support.
Depends on your level of coding expertise I guess, but if a module developer's site is full of unanswered forum posts and you never see them answer a support request here, you may have to hack it yourself if there's a problem.