I've seen lots of "experts" write really insecure code. While it is certainly possible someone did this maliciously. Devs often don't understand the code they write and repeat until they get something that "works" and call it good. With an app that touts security I would hope for better.