"Particularly safe" is a bit alarmist, one could make the same argument about literally anything that connects to a public network isn't particularly safe
It isn't particularly safe compared to having JS disabled. RCE exploits, stealthy CSRFs, etc. that work with JS disabled are exceedingly rare compared their JS counterparts.