Twig automatically escapes the output by default, making Drupal 8 one of the most secure versions yet. For Drupal 7, most security advisors were for cross-site scripting (XSS) vulnerabilities in contributed projects. With Drupal core, these security advisories should be severely reduced using Twig.