Also, since the code is open sourced (https://github.com/wikimedia/apps-android-wikipedia), I guess they get the benefit of the doubt?
It's not being open sourced that leads to secure, well-behaved software.
It's being well-behaved, secure software. Which, among other properties, means following the principles of least privilege and least capability. See the OpenBSD project for more on that philosophy.
That said, Java has a markedly less-than-perfect record.
https://blog.hboeck.de/archives/880-Pwncloud-bad-crypto-in-t...