nah it's a lazy fork so seeing how he chooses people (they're either cheap or friends of friends or both) "truth" can easily have a totally new security issue
maybe the server has a root password that's "trump454748$$$"
The Mastodon developers then formally requested that Truth Social comply with the terms of the software license,[75] with Truth Social publishing its source code as a ZIP file on the website on November 12, 2021.
Lol they actually complied with the license in the end, i didnt know that.
Never saw security flaw now as a real problem. You just have to live with the fact that there is one. And you will suffer when it's used. Security flaw later is a real problem.