Yeah, unfortunately "Easter eggs" call into question the security of the software pipeline.
Did PMs and other engineers review and OK this? -> Suggests a lack of judgement or just rubber-stamping.
Did a lone engineer add this "just to be cute", and it didn't get caught and stopped? -> Proof that your development/release processes are insufficient and you are intensely vulnerable to insider threats.
Neither is good for a security product. At a previous company we were explicitly told that any easter egg was an immediate firing. The company's products had a long history of easter eggs before that.