While this is true, the issue is 'onboarding' a device on to WiFi. Onboarding for some of the devices is through the soon-to-be-discontinued app. So if you ever need to reset or reconnect the device to a network, you're sol.
Why can't these devices' software be certified for safety (FCC, UL) like they do hardware?
First step: reject all devices that propose to ship with weak passwords.