pdaXii13 has other users, ie zaurus, privoxy, etc... which are used when connecting to other systems or allowing access from other systems. it uses root as the active user which shouldn't be a problem compared to other linux systems since the Zaurus is in most cases only used by one user, ie it is not a true multi user system and by default, the zaurus is not connected to the net constantly. telnetd, ftpd and sendmail are not enabled on the zaurus which are the biggest backdoor entries, it has samba (but not started by default) and sshd running, but only non-root users, ie zaurus is allowed access.
one thing is important though, you should set a password for root and zaurus user
if you are really paranoid, install a firewall or setup iptables to block malicious packets or probes...