Not-invented-here (NIH) coders end up worrying about this kind of situation. People who develop "creative" systems by working ground-up starting with foundational system logic. They create proprietary systems really fast, and those proprietary systems often do some wackadoodle things in the name of internal logic.
As a result, those systems are typically harder to maintain or secure by just anybody, even by some experts who are not from the NIH mindset (here's where the author's approach isn't really fair, IMO). Proprietary systems are are less likely to present the typical bell curve security issues that an automated scanner would pick up.
What they are more vulnerable to is puzzle logic--the "what's going on here, hmm let's have a tinker" approach. Which is exactly what the author presented and it also matches his broader approach of "let's have a tinker...with freelancers".
It's a subjective security vs. objective security approach. Both sides are important. But both sides should know about how the other side works.