When someone at work says "Hey, lets just use Xyz package I found online! It does just what we want!" you need to ask: Who fixes it when it causes a problem that stops us from shipping? Who does the security audit? What data does it collect, and to where does it send that data? What will adding it do to our software's performance? Who decides when to update it to the next version and verifies compatibility? Is its license compatible with our workflow/software?
All of a sudden, people are less excited about that great doodad they found on StackOverflow! I'm always troubled by the cavalier attitude about relying on external tools and library dependencies. Yolo just pull it in! In some cases it might be the right decision, but not always. And, avoiding third party stuff is not always just blind NIH mentality: There are costs to depending on someone else for your project.