I’m concerned about using ExpressionEngine because of the fact that it requires PHP. PHP has a horrible security track record and many security bugs have still not been fixed since the ‘Month of PHP bugs’ earlier this year. This is 1 reason why I would like to run Expression Engine using Quercus from Caucho - which is a PHP implementation written in Java. Would EE work with this? Any other customers using EE with Quercus?
One other comment: the portion of your Manual that talks about CAPTCHA is somewhat misleading. CAPTCHA do raise the bar slightly and may act as a deterrent to unmotivated spammers/etc - but they are defeatable. It is simply not true that ‘OCR’ image analysis software can be easily fooled by introducing distortions into the image. In fact - most CAPTCHA implementations have already been defeated.
For example see:
http://www.cs.sfu.ca/~mori/research/gimpy/
http://sam.zoy.org/pwntcha/