Anything can fail, but I would be more concerned about the controller's temp probe failing, or falling out of the water, etc. before I'd worry about the relay failing.
That may be true, but as long as you have a the second security step, why wouldn't you use it? It gives you time to notice the problem before you have well cooked clam chowder.
