Compute the modular exponentiation of base^exponent using algorithms design to avoid side channels and timing measurement
Modulo need to be odd otherwise the normal fast modular exponentiation is used.
When used with integer-simple, this function is not different from expFast, and thus provide the same unstudied and dubious timing and side channels claims.
Before GHC 8.4.2, powModSecInteger is missing from integer-gmp, so expSafe has the same security as expFast.