[eluser]Phil Sturgeon[/eluser]
Haven't had any sites hacked yet. Give it a go, but be nice.
Update: Thinking about one it hole is the login. It is as secure (or more secure) than all of the common auth libraries used around here, but it could really do with saving the cookie/session information in the database. Theoretically a cookie (containing session data) could be forged, but that would be damn near impossible without knowing the encryption key.