I'm sorry, I'm not prepared to accept being insecure by default just because people are too lazy to do some work themselves occasionally.
I mean, if we have such a system in, we'd simply warn any admin that an update is ready, then they go to the admin area, click to update, we pass along the session IDs etc, and the script goes on to import the file, extract it in a temp folder (all of this is very safe...), and then either we ask the user to use FTP to move the folder to the root (i.e. automatically replace all files), or we can offer to do it for them... (Which you wouldn't do, I guess.)
Here's the thing: other platforms don't have one-click upgrades, and they're absolutely happy with this for exactly the same reason I am.
I'd like for it to require as little attention as possible from the admin point of view. SMF upgrades are so painful to me that I simply don't do the upgrades and leave my installs opened to security holes (well, I do try and fix them manually though...)
I'd really like for Wedge to be able to say that "our installed base has zero security holes"...