How many people were capable of spotting a backdoor in the standard[1]? Do you think that an average person can just look at a source code and spot any backdoor or security bug?
Doesn't have to be manual, despite kids being taught programming within the next generation.
Automated fuzzing is a solution amongst others.
It does not have to be the average person. If it's open and if there is enough interest in the community, organizations can contract security professionals to audit the code. This has been done for several crypto projects even in recent history.