Second, would you apply the same line of reasoning to other popular open-source projects, such as Linux or PostgreSQL? Do you believe that those projects are equally insecure?
Linux and PostgreSQL et al would exhibit characteristics of whatever their respective gatekeepers let in.
Btw, I'm not making a definitive statement about Bitcoin's insecurity per se. I'm rather via process of invalidation querying how the ubiquitous claim, that it is an unhackable, secure (basically untouchable) money alternative to fiat, actually holds.
This reminds me of an incident at the beginning of the Ukraine situation when the owner of a heavily used library used in many prominent upstream projects decided one day that his ideological position was so strong that he would initiate a supply chain attack in his code targeting Russian users by IP or something. There was nothing to stop this. That's the nature of open source software.
It's neither trustless nor regulated.