Security shouldn't be much of an issue with most modern CPUs. The microcode can be updated at boot time by the kernel, even if the one loaded by the BIOS is out of date. So microcode level patches are taken care of.
That leaves attacks on secure boot, which could be feasible with a bad implementation, but I doubt most home users would have to worry about an evil maid attack.
That leaves attacks on secure boot, which could be feasible with a bad implementation, but I doubt most home users would have to worry about an evil maid attack.