This is the right answer. Basically nothing is secure. That’s the truth. There will always be a hole or a way to circumvent something. That said, a lot of open source software is very high quality and I use it where I can because it’s free and some conglomerate is not push ads or siphoning info from me.
Plex user for over a decade and my only gripe is lack of accounts when internet goes out. When I’m self hosting, I kind of consider it a baseline for something like authentication to a local self hosted server to work without an internet connection.
Also the “recommended” bullshit. What the fuck. I know hat I’m hosting. I know what I download. Why does plex feel the need to force this as the default landing page? Honestly I with jellyfin was a bit more mature cause I’d use that instead.
I’m a network engineer and >15 years of experience in IT. It’s never “safe”. Not even in corporate IT. You’re a home user and it’s less likely you’ll be targeted but bad actors do comb the internet for known vulnerabilities. Patch your shit, limit exposure, enable MFA on everything. I don’t run it, but I feel slightly sketched out not behind something like a Palo Alto. But again I’m just a small potato in a big sea and I patch everything.
There will always be risk. Just do what feels right for you. Follow beat practices.
This is what I do. I have a truenas server and it runs docker containers for couch potato, medusa, transmission, and plex. When shows are released they just show up in plex as if it were Netflix. Easy. No red tape on finding out which streaming service etc. It will just arrive all in one place. Best of all there’s a good app to manage it all from your phone. Nzb360
They’re still way better than cheap shit office chairs