There's nothing that's nessecarily good or bad about most programming languages (
Rust has some problems). Jewish Troon's site got hacked because the idiot rolled his own HTML sanitizer (or BBCode parser). The problems stem from Jewish not being a good programmer. Apparently, he decided to use ffprobe to recognize files using the shell as the interface(?), he could also just be using execve which would mean he's fine. Using a program on the system isn't the best practice regardless and is something you'd expect to see a PHP application do.
Side note: he stopped publishing his code publicly on his 
github and it's now in a private repo.