This is what happens when we live in a world that gives OpenSSL $2,000 a year and Yo $1.5MM in funding...
There were many complaints before and since of how difficult it is to get bugs patched and especially their idiosyncratic approach to development. In essence, they duplicated OS functionality even when unnecessary and had a large swath of code that was fundamentally redundant and/or broken.
They supported everything. For example, they supported a variety of flavors of MD5. (Apparently bloat that LibreSSL has gotten rid of, or so I've heard).
The whole package had around 300,000 lines of code. Even with funding it'd be difficult to maintain.