i would have thought that somebody already found that out – with 100000 of distributions so far…^^
for the public area i can install a code highlight plugin. some are capable of securing the output (most are not!).
but for the admin area i am not sure how to implement security hacks.
just started to use wordpress – and i am shocked.
those things are absolutely standard procedure in every web project