I don’t think friendly urls are any more inherently secure... it’s more like "security through obscurity", which isn’t a good way to go. MODx has had in the past a couple cross-site scripting vulnerabilities (eep!)
I posted a video for enabling SEO friendly urls:
http://www.youtube.com/watch?v=JlGiypZZTSw
There are a couple tips in there for testing to see if Apache is parsing your .htaccess file.