"...if it is, it is save for 'normal' users as well..."
Not sure about that. I think even if a power user were to say "this is safe", you still have a boatload of integrity problems with the software.
-How do we know the power users can be trusted?
-Even if they can, what guarantee do we have that the service provider we use is using the same open source code that the power user validated?
-Etc, etc, etc. Basically, a lot of trust issues.
I agree with asadlionpk, open source can generally only be proven to help power users in a trustless environment. And where security is concerned, we cannot ascribe the "safe" attribute to any system where that safety cannot be proven.