If massive companies like Google and Apple can’t even find all the vulnerabilities, how are you expecting a scrappy team to?
Don’t get me wrong, how far they’ve gotten is very laudable and as a educational exercise it is really cool, but it starts being a pretty massive risk if users start using this as a daily driver.
Google and Apple are just a bunch of scrappy teams trying to work together on insanely massive and bloated code bases.
Numbers of bugs scale with lines of code.
Small scrappy team writing simple and consice code from scratch is likely to produce fewer bugs than enterprisey monstrosities.