Earlier quoted context omitted.
Being open source doesn't actually save you from exploitable vulns related to integer arithmetic.
I enables independent, non-involved, non-interested parties to check it. Also when the protocol is open, it enables multiple implementations; keeping a known-by-few trojan style bug in all of them is specially difficult.
Nice theory, but most of the time it's "just use zlib, bro, it's battle tested".