No it doesn't, those are two different points.

1. OP was surprised that a technoglogy that is very popular exists

2. OP assumed JavaScript is magically insecure as a language with no qualifiers. We were talking about server-side JS, so your entire screed about client-side makes no sense at all.

I hate it when people who don't know anything about a topic run off on things they don't understand.

P.S. None of your "attacks" can target client-side frameworks, that's ridiculous because all of that code runs client-side.

