Vim security
I've just read https://glyph.twistedmatrix.com/2015/11/editor-malware.html and https://jordaneldredge.com/blog/why-i-switched-from-vundle-to-plug/ which both discuss some issues about text editor security.
TL,DR:
- vim-plug is preferred to vundle
- developers may be seen as high value targets for system compromise.
- beware git:// protocol