I've got a custom-built Q&A website built on Ruby-on-Rails at mysite.com; it's not rocket-science but does have a lot of custom functionality. I host the site's blog at mysite.NET (which I also own, in addition to the .com). I know this is subpotimal for SEO-juice-consolidation purposes, so in an ideal world I'd have the blog hosted at blog.myspace.com.
One of the reasons I haven't done so yet, though, is because I'm worried about site security. I've had several Wordpress blogs in the past that were hacked -- usually, I believe, because of installing insecure WP plugins, or not updating old plugins. So I don't want to install Wordpress at mysite.com if it means that it could create security vulnerabilities for the entire myspace.com domain. In short, is it possible to install WP in a way that -- even if it were compromised -- would ONLY compromise the blog portion of the domain (at blog.mysite.com)? I simply can't risk the ENTIRE custom-built Q&A site getting compromised...