2
it's pretty damn secure actually.. far more so than php nuke & then some!!
it can pretty much tackle the majority of script kiddies, & possibly a fairly good hacker.. but nothing in this world is 100% secure.. but the devs take security very seriously.. so any exploits or vulnerabilities are fixed in little time once identified..
there's other ways tho, that may not include hacking thru xoops.. so it's upto you to make sure ur servers are secure too.. :)