here's his further reply in full
Hi Tim,
Thanks for the reply, hackers will try to analyze your scripts and hacked all of these sites, actually on the internet there are some hackers use auto scan script to find out server which is running unsafe scripts.
If you only use this script, not try to develop your business version, so that's should be more safe, but in general this kind of scripts use xml rpc method, there were some report said their xmlrpc.php being exploited, also the most of security scripts only protect login form -- x.domain.com/wp-login.php, not protect xml rpc, a option of my secure plugin is close xml rpc, because it is easy to write a auto script to "guess" the password, if you use admin as your administrator username, in this case, if you have an automatically backup script, it should be more safe. But if you are try to build site groups, use this kind of services have a big help of course -- the problem is balance and the risk, from my eyes, if you build more than 30 sites, use it is a good choice, just need to install some other secure plugin -- but this will caused another problem, if so your site will be more "heavy", also you need check your site per week to find out are there any site is running fail, in this case, backup is very important, thanks.
Best Regards,
Tomas