Why is it that the Java internet plugin is so vulnerable to zero-day exploits?

Is it just badly written code?

Are developers constrained in terms of how secure they can write their code due to the purpose that the plugin is fulfilling?