I put some scripts in workspace models, and am curious how safe is that against hackers while having FE on
Perfectly safe - exploiters cannot modify server scripts, no matter where you put them. However, they can add or remove LocalScripts (for themselves only) - this is one of the reasons why you should never trust the client.
I go into detail into what exploiters can do here: https://scriptinghelpers.org/questions/51968/anything-helps-someone-tell-me-more-about-fe-pls