Really depends on your threat model; I think most companies stop short of shipping malware from their UEFI implementation. That said, I don't think Framework has yet done anything questionable?
The problem with Framework is that BIOS updates are really rare. I been running the 3.0.6-beta for my 12th gen for almost 8 months I think and the full release has yet to come. I bet it will never happen as they are focusing on AMD and 13th gen + 16" one at the moment.
At least the 12th gen is very vulnerable to hardware access as you can't disable unauthenticated DMA access through the USB ports (it's what https://www.dell.com/community/en/conversations/latitude/dem... calls SL0). I asked their support and they aren't planning to fix it in the forseeable future.