I'd assume there's some basic attacks that could be performed in person since there's no ssl, but besides that, I'd assume the sites fairly secure if you use 2fa.I do cyber security work, so I can check to see if the site is vulnerable to any malicious behavior if you want.
Ssh requires a decently long password or a certificate, and the admin panel requires you to log in again every time you go to it


