Rand,
I'm in the midst of a conversation with web security folks who state that a sub-directory (e.g. website/blog) that points to a blog like WordPress via a reverse proxy bypasses the "same-origin policy" and puts the site at "high risk".
If we take the standard security "hardening" measures like quality managed hosting with blog files kept separate from customer information, regular updates, trusted themes, vetted plugins, backups, etc., shouldn't we mitigate that risk?