Open-source risk
Open source is neither inherently more nor less secure than commercial software. It fails differently.
The code can be inspected, which helps if anybody actually does. There is no vendor obligated to respond, which hurts when something is found. Risk depends on the specific project: how many maintainers, how active, how widely reviewed. The licence model is not the variable that matters.
Checked against the primary source.
