Plex user for over a decade and my only gripe is lack of accounts when internet goes out. When I’m self hosting, I kind of consider it a baseline for something like authentication to a local self hosted server to work without an internet connection.
Also the “recommended” bullshit. What the fuck. I know hat I’m hosting. I know what I download. Why does plex feel the need to force this as the default landing page? Honestly I with jellyfin was a bit more mature cause I’d use that instead.
I’m a network engineer and >15 years of experience in IT. It’s never “safe”. Not even in corporate IT. You’re a home user and it’s less likely you’ll be targeted but bad actors do comb the internet for known vulnerabilities. Patch your shit, limit exposure, enable MFA on everything. I don’t run it, but I feel slightly sketched out not behind something like a Palo Alto. But again I’m just a small potato in a big sea and I patch everything.
There will always be risk. Just do what feels right for you. Follow beat practices.
Yeah I’m only running it because truenas scale uses it