'open source is less secure'

The claim does not survive contact with the evidence in either direction.

Widely used open source components are frequently reviewed by more people than proprietary equivalents. Obscure ones may be maintained by nobody. Commercial software has both dedicated security teams and code nobody outside can examine. Judging by the model rather than by the specific project and its maintenance is the error.

Checked against the primary source.

More on Supply chain and third parties