It’s on by default in yarn 4 too now, but pnpm was the first to market that default minimum gate.
Many places run analyzers on published code; many security users have reason to shorten the period. The default period becomes the period where white hats have a chance to detect it and stop it passing the threshold.
I guess it could work better if it was enabled for only actual attack vectors projects.