more seriously:
1. Reading the full source code can be quite difficult and time consuming, and being able to spot security issues is even harder. Some experts miss those until someone stumbles upon it, or is dedicated enough to look deeper...
2. there's an underlying assumption that if something is open-source, then the 'many eyes principle' applies, and someone has looked at the code. So whilst it's generally true, it might not always apply to security. Many might have looked at the code, but unless they were specifically looking for security, and were qualified enough to find the more subtle, hidden security issues - those will go unnoticed.
The general rule of thumb to look for stability indicators, applies to security to a large extent: activity on the project, number of 'stars' on github, reputation of the core committers etc. But even then there's no guarantee.
If you want to stand on shoulders of giants, you'd have to trust those giants to support you.