>>9Things can be hidden in plain site. It’s called stegsnography or obfuscation. Or someone could just submit code that is insecure knowing that it’s insecure and pretend that they didn’t know.
The problem with open source is that everybody assumes someone else will audit the source code.
But when was the last time you looked over the entire source? Besides, if you use binaries instead of compiling from source, it might not be the same as the source code they provide.