A client mode device isn't any safer unless it's on it's own physically separate LAN.
If you open a port on the router, an external host can send to that port. Assuming it's not a port that's used on your other equipment, only the new device will receive those messages. It may then do something in response, to the LAN it's connected to. You have no control over what it can do to other devices on that LAN but they can't be accessed directly from the external host : they're not listening on the open port. Of course, if it opens a port used by existing services all bets are off but you indicate that's not the case.
If you have a client device that accesses some remote host without opening an external port, it can still receive instructions via the connection and then has exactly the same access to the rest of the LAN it's connected to.
If you need to put a device you don't trust inside your LAN, it doesn't matter how that device connects with it's vendor, as client or server. You need to put it on it's own physical subnet. You might do this with a router capable of operating several subnets - either wired or with different wifi credentials, or it can be done with a secondary router. The name for this is a DMZ or demilitarized zone and has been used for years to separate devices such as webservers which, even if you set them up initially, may be compromised due to the essential access they have from outside users. The idea is that devices within the DMZ have access to the internet and may be accessed from the internet, but they don't have access to your private systems.