you're not getting much extra safety in exchange for using an experimental compiler
It's Clang/LLVM, with just a little extra code added around pointer dereferences.
That's still in "experimental" stage and you don't know what this extra code could introduce in terms of bugs. Judging from a few of the reported issues (
https://github.com/pizlonator/fil-c/issues ), it looks far from being production-ready.
I personally agree with 5U4GB, I wouldn't trade a robust and standard compiler for something experimental. Unless, of course, for experimental use. No problem with that.
The performance hit seems pretty severe too, as expected. Yes, you said that it's probably not in real-life cases, but do we know? Are there actual benchmarks on real code? I suspect that it probably has a significant impact on compression and decompression code, which is ubiquitous.
I think (again my take here) that it may be more interesting as a test tool than as a "production" compiler. See what it's able to catch if anything, and fix code accordingly. There are actually tons of tools, both static and dynamic, that can do this, and I'm always surprised seeing how very few people use them.
Now, we know rewriting software has a high cost and almost invariably introduces a whole series of new bugs, so keeping code as is and using a different compiler producing "safer" executables looks like a reasonable idea. But it has been tried before and has never caught on, so, we'll see (I wouldn't bet a dollar on Fil-C, but that's just my opinion at the moment).
One thing that should IMO be integrated into compilers for ANY language is to force developers to add input validation of every single function (with a possibiity to escape that for specific performance reasons with extra keywords, making it annoying enough not to be "default"). Of course, that's a different approach, not a "drop-in" replacement: that would require writing better code and re-writing existing code that doesn't comply. The lack of input validation accounts for a gigantic proportion of bugs in general and security-related bugs in particular. I don't even quite remember the last time when I saw a security report that wasn't linked to a lack of input validation.