are you sure? How can you be sure that your custom patches didn't affect the security of the core product? qmail wasn't designed to be extensible. It had no plugin interface.
Of course it's possible that you didn't make a mistake back then.
Just as it's possible that I didn't make a mistake when I was 18 and wrote a patch to Cyrus imapd to allow authenticating against an SQL database.
But TBH, when I look back at the code I wrote back then, at least in my case, I'm quite sure I f'ed up in various ways.
Thankfully, I never shared these patches with other people.