When a new widget is created from an existing web part, all the attributes are hidden in the editing form by default. It is up to the widget creator to select attributes which should be available for customization using check boxes on the Properties tab.
The security options are defined on the Security tab when selecting a widget from the content tree at Site Manager -> Development -> Widgets. By default, all widgets are forbidden for all zone types and are allowed for authorized roles only. However, no authorized role is selected by default. It is up to the developers to allow the widget for a specific type of zone and role.
Please keep in mind that changing the security settings will affect new widgets only. If a user was allowed to add a widget and an administrator later removes this permission, the user can still see the widget on their page. However, once deleted, the widget cannot be added back to the page without allowing it on the Security tab of that particular widget.