If you're actually schizo about it, turning off the frontend entirely and just using mastoapi with whatever clients is a savage way to run an instance.
You basically BTFO of any theoretical vulnerabilities that could exist. Also it raises the bar for fedicock no lifes trying to recon your instance.