Are these concerns valid?: https://forum.cryptpad.org/d/232-onlyoffice-concerns-vendor-...
Some parts of their portfolio are not FOSS, these are the components in the commercial edition (the hosted/embeddable version of onlyoffice).
I have customers running OnlyOffice and we've never seen anything suspicious in our security tooling.
So I believe it comes down to your opinion/mindset around the whole Russia thing.