Timthumb did have a major security vulnerability many years ago, which had been quickly patched. Most of the hacks you’ve heard about were from users [or plugin authors] who failed to update and get the patch applied. AFAIK it’s completely safe these days. But generally speaking, allowing uploads from any one that happens along is going to decrease you security no matter what. At least only allow uploads from logged in users and apply any other restrictions that are reasonable.
]]>