I mean it should be pretty safe if it’s local only. If your network is compromised jellyfin is the least of your worries.
Switch to mobile data and put the public ip of your network and the jellyfin port in a browser and make sure it can’t be accessed
It gets more confusing when you read their user name