It being a simple NTP client and not a server means that it has a vastly reduced attack surface. That's good. But that doesn't mean we shouldn't wait and see how buggy it actually is.
And their named DNS daemon was to be a stub resolver. Then it grew a cache. And now it seems to have developed a insecurity that most other DNS daemons out there dealt with a decade ago...