Yunohost is probably more secure than you figuring everything out yourself. More people have a vested interest in keeping it secure. They have a minimal page on security but they have fail2ban, unattended upgrades,and a secure SSH configuration. If something is discovered, you might be vulnerable but at least there will be knowledgeable people fixing it.
Security is always difficult and nothing is 100% secure. The three letter agencies around the world have been hacked and they are in the business of hacking others. Hackers themselves get hacked on the regular. Using yunohost as a noon probably reduces the chance of you getting hacked.
If you have something only you need to access, you can also host yunohost for yourself and make it accessible only via a VPN. Headscale, tailscale, maybe even your router provides a VPN service, or setup wireguard yourself. If others have to access it... I dunno. That's a good question to ask on /c/selfhosted
I don't support the views of the endorsed projects, but surely a better reaction would be to suggest alternatives instead of just screaming for outright dismissal? I keep reading that "omarchy is just a bunch of scripts" and "hyperland is just one tiling window manager". If that's the case, there probably are better alternatives no? Or if it's as easy as described why not fork it?
Complaining without an alternative or a solution is not productive, IMO