Quite honestly, I think that if companies paid open source maintainers to get the features they wanted, the log4j problem would NOT have been averted at all, it would likely have happened earlier... notice that the source of the issue (support for JNDI lookups right into any log messages) was introduced because of someone asking for that feature (and getting it for free!)... if a company had paid for it, it would've been just the same, I doubt very much the company would have done any kind of security veto on the implementation.
What's needed is for open source libraries to somehow get "rated" by security experts before they get used by businesses. If those businesses using it paid for that, and then paid someone to fix any issues found, then I think we would have a working solution. Just paying for features would just make things worse... have you ever seen companies paying for security features, though?? No, I haven't at least... they pay for business features that will make them money, they hope, security is kind of just implied (and they might lay the blame entirely on the developer if they actually had a business relationship with them - which may be a big nightmare, actually, for OSS developers - and I am one of them myself... you can no longer use a license that just says you're not liable to anything bad that happens).