As a positive thing, maybe at least nixos will get a serious security pipeline rather than the current best-effort community approach.
I'm not sure why they chose nix. But it does make it easier to carry local patches than a lot of other systems. I hope they succeed.
This is the main issue NixOS solves for me. I don't have systemd units or cronjobs or random config files spread across the system. I have one config file/directory, which contains everything.
My beef with nix is the arcane syntax to get anything done. Yes, it's documented. No, it doesn't help that it reads like one of those strict, convoluted standards written by a committee of experts.
Also what causes problems for others may not be the same thing that causes problems for you. You could try accepting others' experiences.