Some day, just for fun, I have broken some gov site using expresso. I got full remote code execution (for test, I just uploaded a php file with a phpinfo()). And I'm not a security expert. I think my govern has a lot of work to do to make their email more secure...