I stopped using procmail after I managed to crash it with a long regexp. It's been more than 10 years, but I think it was a simple, but very long alternation of simple terms, and that it buffer overflowed. While not in a security sensative part of the code, that was close enough to put me off it. Although I have not been very happy with maildrop either.