Right. Software that has never had a vulnerability is either 1) software that has never had careful scrutiny, 2) software that has no potential security implications whatsoever, or 3) software that has gone through some formal verification and proof process (exceedingly rare).
Nonetheless, the posterior distribution shifts based on new evidence.
Are you making a claim about which one is more secure? I'm genuinely curious about how they stack up against one another. pdf.js is obviously managed code, which I'm sure helps. But it also seems like it has less person-power behind it, now and historically. Do you agree with that perception? Why or why not?
But I don't think that it's particularly relevant to security whether 3 people or 30 people work on a project. Both Chrome and Firefox are fully maintained with top-notch security teams.