You can check e.g. Signal is not backdoored by reading the source code. You can find it here https://github.com/signalapp/
You can vefify the client you downloaded from Play Store hasn't been tampered with. Instructions for that are here: https://github.com/signalapp/Signal-Android/tree/master/repr...
Your post is slightly ironic, considering Telegram doesn't give you any choice on using E2EE for groups or any chats for that matter, on majority of desktop clients. Know this: when you're not using end-to-end encryption, i.e. when you're using Telegram cloud chats, those chats are by definition as private as a backdoored E2EE chat would be. So one could argue they are front-doored by design.
Also, what about the server source code?
>Also, what about the server source code?
https://github.com/signalapp/Signal-Server There you go, last commit two days ago.
That's not how it worked out for email long-term; why should IM be any different?
Regarding Riot, which is called Element by now, you may want to update your knowledge
"It's not a quality guarantee for clients in practice since you can't control Client Side with open source"
What? Open source native client with reproducible builds is literally the gold standard of individual control over software, it's even GPL licenced.
Signal responded to the server code being outdated as well: https://github.com/signalapp/Signal-Android/issues/11101#iss...