How many people were capable of spotting a backdoor in the standard[1]? Do you think that an average person can just look at a source code and spot any backdoor or security bug?
1. https://www.wired.com/images_blogs/threatlevel/2013/09/15-sh...
1. https://www.wired.com/images_blogs/threatlevel/2013/09/15-sh...
Automated fuzzing is a solution amongst others.