The author's argument is that we shouldn't just have to wait for time to determine the security and/or plausibility of this solution. It is probably true that eventually we will know if Haystack is effective or not. But we would know a lot sooner if the code were available.
It's not that there's security bugs or buffer overflows in some software. Everything has bugs and if the design and idea is good, they can usually be fixed and everything can keep moving along fine. It's that we know essentially nothing about the implementation or design of a program that asks its users to trust it to keep their traffic safe from an oppressive government. I think you'd have to be awfully naive to just take Haystack at its word that Haystack actually works.