If they are, they are either only exposing specific containers, or they aren't following recommended practices.
For now, NONE of the base services except wireguard on Unraid should be forwarded to the internet. Wireguard is built in now, and there are multiple other ways to get secure access in to manage your server, but Unraid SSH itself should not be exposed.
Unraid is not a general purpose slackware box, it's just not meant to be used that way right now. We are slowly progressing towards being able to secure Unraid, but for now, keep it fully behind a proper firewall.